A Surgeon, a Sales Rep, and a $26 Million Settlement Walk Into a Courtroom

In 2023, Amedisys Inc. agreed to pay $26 million to resolve allegations that it violated the Anti-Kickback Statute (AKS) by paying bonuses to employees who generated patient referrals for home health services. The Department of Justice didn't mince words — the company's arrangements were designed to reward referrals, plain and simple.

If you've been focused purely on HIPAA's Privacy Rule and breach notification requirements, you might wonder why this matters to you. Here's the short answer: the anti kickback statute applies to virtually every transaction, arrangement, and referral relationship in healthcare that touches a federal health care program. And in my experience, it's one of the most misunderstood laws your compliance team needs to master.

This post will break down exactly who the statute targets, how it overlaps with your HIPAA obligations, and what your organization can do right now to avoid becoming the next cautionary tale.

What the Anti Kickback Statute Actually Says — In Plain English

The federal Anti-Kickback Statute, codified at 42 U.S.C. § 1320a-7b(b), makes it a criminal offense to knowingly and willfully offer, pay, solicit, or receive anything of value to induce or reward referrals of items or services reimbursable by a federal healthcare program. That includes Medicare, Medicaid, TRICARE, and CHIP.

"Anything of value" is where organizations trip up. I've seen compliance officers assume the statute only covers briefcases full of cash. It doesn't. It covers gift cards, lavish dinners, below-market-rate office leases, sham consulting agreements, and even certain marketing arrangements.

Who Does the Anti Kickback Statute Apply To?

The anti kickback statute applies to anyone who offers, pays, solicits, or receives remuneration in connection with a federal healthcare program referral. That's a wide net. Specifically, it catches:

  • Physicians and physician groups who receive payments tied to patient referrals
  • Hospitals and health systems structuring recruitment deals or joint ventures
  • Pharmaceutical and device companies paying speakers fees, consulting fees, or offering rebates
  • Home health agencies compensating employees or partners for generating referrals
  • Laboratories offering processing agreements that function as referral incentives
  • Durable medical equipment (DME) suppliers providing kickbacks to prescribers
  • Electronic health record vendors offering discounts that don't meet safe harbor requirements
  • Any covered entity or business associate whose financial relationships could influence referral patterns

Notice this isn't limited to the person receiving the kickback. Both sides of the transaction face criminal liability.

The HIPAA Connection Most Compliance Officers Miss

Here's what I tell every client: HIPAA and the Anti-Kickback Statute live in the same ecosystem. When a kickback scheme operates inside a covered entity, it almost always involves the misuse of protected health information.

Think about it. To generate referrals, someone needs patient data — names, diagnoses, insurance status, treatment histories. That's PHI. When staff members mine patient records to identify referral candidates for a kickback arrangement, they've created a HIPAA violation on top of an AKS violation.

HHS and the Office of Inspector General (OIG) coordinate investigations. A single whistleblower complaint can trigger both an OIG investigation into kickback activity and an OCR investigation into improper PHI access. I've watched organizations face penalties on both fronts simultaneously.

When Kickbacks Trigger Breach Notification

If employees access ePHI without a legitimate treatment, payment, or healthcare operations purpose — say, to identify patients for a kickback-fueled referral scheme — that constitutes an impermissible use under the HIPAA Privacy Rule. Depending on the scope, it could also trigger breach notification requirements under HHS rules.

Your organization would then face the nightmare scenario: reporting the breach to OCR while simultaneously being investigated by the OIG for fraud. The financial and reputational damage compounds fast.

Real Penalties That Should Keep You Up at Night

AKS violations carry serious consequences. Each violation can result in:

  • Criminal fines up to $100,000
  • Up to 10 years in prison
  • Exclusion from all federal healthcare programs
  • Civil monetary penalties up to $100,000 per violation, plus treble damages under the False Claims Act

The exclusion piece is the real business killer. If your organization gets excluded from Medicare and Medicaid, you're effectively shut down.

The 2024 Encompass Health Case

In 2024, Encompass Health agreed to pay $48 million to settle False Claims Act allegations rooted in AKS violations involving improper relationships with referring physicians. The DOJ alleged the company provided above-fair-market-value compensation to physicians who referred patients to its rehabilitation hospitals.

This wasn't a small clinic cutting corners. This was a publicly traded company with a compliance department. The anti kickback statute applies to organizations of every size, and enforcement actions prove that resources and sophistication don't provide immunity.

The OIG has established safe harbor regulations that protect certain payment arrangements from AKS prosecution — but only if every element of the safe harbor is satisfied. There's no partial credit.

Key safe harbors include:

  • Personal services and management contracts: Written agreements, fair market value compensation, commercially reasonable terms
  • Space and equipment rental: Written lease, consistent with fair market value, not determined by referral volume
  • Employee compensation: Bona fide employment relationships with W-2 employees
  • Discount arrangements: Properly disclosed and accurately reported
  • EHR donations: Meeting specific criteria around interoperability and cost-sharing

In my experience, the most common failure point is fair market value documentation. Organizations handshake a deal, never get a formal valuation, and then can't prove the arrangement was legitimate when investigators come knocking.

How Workforce Training Prevents AKS Disasters

Every enforcement action I've studied shares a common thread: staff didn't understand the rules. Physicians didn't know their speaking arrangement was problematic. Marketing teams didn't realize their referral bonuses crossed a legal line. Compliance officers assumed the AKS was "someone else's problem."

Your workforce training program needs to cover the Anti-Kickback Statute alongside HIPAA. These aren't separate universes — they're overlapping obligations that your staff encounters every day. When your team understands that improperly accessing PHI for referral purposes creates dual liability, behavior changes.

Our HIPAA training catalog addresses the intersection of fraud, abuse, and privacy compliance in a way that resonates with clinical and administrative staff alike. If your current training doesn't mention the AKS, you have a gap.

What Should Your Training Cover?

At minimum, your workforce needs to understand:

  • What constitutes "remuneration" under the AKS (hint: it's broader than they think)
  • How referral-based compensation triggers both AKS and HIPAA risks
  • The obligation to report suspected kickback arrangements internally
  • How safe harbors work — and why "close enough" doesn't count
  • Real enforcement examples that make the stakes concrete

Building this into your compliance training program takes the AKS from abstract legal theory to something your staff can actually apply.

Five Steps to Audit Your AKS Risk Right Now

You don't need to wait for an investigation to find problems. Here's what I recommend to every covered entity I work with:

  • Map every physician and vendor financial relationship. If you can't list them all, that's your first red flag.
  • Verify fair market value documentation. Every lease, consulting agreement, and speaking arrangement needs a defensible FMV analysis.
  • Audit referral patterns. Look for correlations between financial arrangements and referral volumes. Investigators will.
  • Review access logs for PHI. Identify any staff accessing patient records outside their job function — this catches both HIPAA violations and potential kickback-related data mining.
  • Update your compliance training. If your last training session didn't mention the Anti-Kickback Statute, schedule a new one through a comprehensive HIPAA and compliance training program immediately.

The Question That Determines Your Risk Level

Here's the litmus test I use with clients: "Would this financial arrangement exist if the referrals stopped?" If the answer is no — if the only reason you're paying someone is because they send you patients — you have an AKS problem. It doesn't matter how the contract is worded or what your attorney told you five years ago.

The anti kickback statute applies to the reality of the arrangement, not just the paperwork. The OIG looks at intent, conduct, and outcomes. Your documentation matters, but it won't save you if the underlying relationship is designed to buy referrals.

Don't Wait for the Subpoena

Federal healthcare fraud enforcement is intensifying. The OIG's work plan for 2026 specifically targets referral relationships, telehealth arrangements, and clinical laboratory compensation structures. If your organization participates in Medicare or Medicaid — and most covered entities do — you're in the crosshairs.

Get your financial relationships documented and defensible. Train your workforce on both HIPAA and AKS obligations. Audit your referral patterns before the government does it for you.

Because in this regulatory environment, the organizations that survive aren't the ones that never made mistakes. They're the ones that found the problems first and fixed them.