A Referral Bonus That Cost a Health System Everything

In 2023, a Florida-based lab company agreed to pay $16 million to resolve allegations that it paid kickbacks to physicians in exchange for patient referrals. The payments were disguised as "consulting fees" and "marketing agreements." But here's the part most compliance blogs skip: those referral arrangements also involved the improper sharing of patient data — PHI that moved through channels it never should have touched.

The anti kickback statute in healthcare doesn't just live in the fraud prevention lane. It intersects with HIPAA in ways that catch compliance officers off guard. If your organization handles referrals, partnerships, or any arrangement where money and patient data flow together, you need to understand this overlap.

I've spent years watching organizations treat the Anti-Kickback Statute (AKS) and HIPAA as separate silos. That's a mistake that gets expensive fast.

What the Anti Kickback Statute Actually Prohibits

The federal Anti-Kickback Statute, codified at 42 U.S.C. § 1320a-7b(b), makes it a criminal offense to knowingly and willfully offer, pay, solicit, or receive anything of value to induce or reward referrals for services covered by federal healthcare programs. That includes Medicare, Medicaid, and TRICARE.

"Anything of value" is deliberately broad. Cash, gift cards, above-market rent, sham consulting agreements, lavish dinners — the OIG has seen it all. The statute applies to both sides of the transaction: the person offering the kickback and the person receiving it.

The Safe Harbors You Need to Know

The OIG has established regulatory safe harbors that protect certain payment arrangements from prosecution. These include legitimate employment relationships, personal services contracts with fair market value compensation, and certain investment interests. You can review the full list on the OIG's safe harbor regulations page.

But here's the catch: safe harbors have strict requirements. Miss one element and your arrangement is exposed. I've reviewed contracts where organizations thought they were protected because they had "a written agreement." That's necessary, but nowhere near sufficient.

Where the Anti Kickback Statute and HIPAA Collide

This is where it gets real for your HIPAA compliance team. Every kickback scheme involving patient referrals requires the movement of patient information. Someone has to identify which patients to refer, track whether referrals were completed, and often share clinical data to justify the services billed.

That means PHI is being used, disclosed, or accessed for purposes that have nothing to do with treatment, payment, or healthcare operations — the three pillars of permissible use under the HIPAA Privacy Rule.

Improper Access to ePHI for Referral Tracking

In my experience, the most common scenario looks like this: a practice manager pulls a list of patients with specific diagnoses from the EHR, then shares that list with an outside lab or imaging center as part of an under-the-table referral arrangement. That's a HIPAA violation layered on top of an AKS violation.

The covered entity just disclosed PHI without a valid basis. No Business Associate Agreement. No patient authorization. No treatment, payment, or operations justification. And the person who pulled the data likely accessed ePHI beyond the scope of their role — a workforce training failure that compounds the problem.

Business Associate Agreements Won't Save You

Some organizations try to paper over these arrangements with BAAs. But a BAA doesn't make an illegal kickback relationship legal. If the underlying arrangement violates the Anti-Kickback Statute, the data sharing that supports it lacks a lawful foundation under HIPAA. You can't build compliant data sharing on top of a fraudulent business relationship.

Real Enforcement: When AKS and HIPAA Violations Stack Up

HHS and the OIG don't operate in isolation. The Department of Justice frequently coordinates with OCR and OIG to pursue cases where healthcare fraud and privacy violations overlap.

Consider the 2022 DOJ case against Advantage Therapy Solutions, where the company paid $6.9 million to settle allegations of kickbacks paid to assisted living facilities for therapy referrals. The underlying conduct involved accessing and sharing resident health information to drive the referral pipeline. When federal investigators pull on the AKS thread, they almost always find HIPAA threads attached.

OCR's own enforcement history reinforces the point. When OCR investigates a breach and finds that PHI was disclosed to unauthorized parties in connection with a financial arrangement, the penalties escalate. OCR has settled cases for amounts ranging from $100,000 to $5.1 million depending on the scope and willfulness of the violation. The 2018 settlement with MD Anderson Cancer Center for $4.3 million, while centered on encryption failures, demonstrated OCR's willingness to impose significant penalties when systemic compliance failures exist.

How Does the Anti Kickback Statute Affect HIPAA Compliance Programs?

Your HIPAA compliance program should address AKS risks directly. Here's how they connect:

  • Risk analysis: Your HIPAA risk analysis should identify scenarios where PHI might be accessed or disclosed in connection with referral arrangements, marketing agreements, or vendor relationships that could implicate the AKS.
  • Workforce training: Staff need to understand that sharing patient lists, diagnosis information, or contact details with outside entities for referral purposes — without proper authorization — violates HIPAA regardless of whether anyone calls it a "kickback."
  • Access controls: Role-based access to ePHI should prevent employees from pulling patient data for purposes outside their job functions. If a billing clerk can export a list of every patient with a specific diagnosis, your access controls are too loose.
  • Incident response: When your organization discovers a potential AKS violation, your breach notification procedures should activate simultaneously. If PHI was improperly disclosed as part of the scheme, you may have a reportable breach on your hands.

Building this awareness into your training program is essential. Our HIPAA training catalog includes modules that help workforce members recognize when data-sharing arrangements cross legal lines.

Five Red Flags Your Compliance Team Should Watch For

After reviewing dozens of AKS-related investigations, I've identified the patterns that show up repeatedly:

  • Referral volume tracking: Any arrangement where compensation correlates with the number of patients referred is a classic AKS red flag — and it almost always involves PHI-based tracking.
  • Vague consulting agreements: If a physician is paid for "consulting" but the only deliverable is patient referrals, the arrangement likely violates the AKS and involves unauthorized PHI disclosure.
  • Patient lists shared without BAAs: Sharing identifiable patient information with entities that aren't business associates and don't have patient authorization is a HIPAA violation, period.
  • Above-market compensation: Rental agreements, service contracts, or employment arrangements that pay significantly above fair market value often serve as vehicles for disguised kickbacks.
  • Marketing that targets specific patients: When a vendor asks for patient contact information to "market" services, and your organization receives compensation for those referrals, you're in dual-violation territory.

Building a Defense That Actually Works

The organizations that avoid these problems share three characteristics. First, they train everyone — not just compliance staff, but front-desk workers, practice managers, and IT personnel — on the intersection of fraud and privacy law. A well-structured workforce training program addresses both.

Second, they audit referral arrangements annually. Not just for AKS compliance, but specifically examining how PHI flows through those arrangements. Who accesses the data? Where does it go? Is there a lawful basis for every disclosure?

Third, they create clear reporting channels. Employees who notice suspicious referral patterns or unusual data access need a way to report concerns without fear of retaliation. The best compliance programs I've seen treat these reports as early warning systems, not problems to be managed.

The Bottom Line for Your Organization

The anti kickback statute in healthcare isn't just a fraud issue. It's a PHI issue. Every improper referral arrangement creates a data trail, and that data trail almost always involves protected health information moving where it shouldn't.

If your HIPAA compliance program doesn't account for AKS risks, you have a gap. And gaps like this don't stay hidden. They surface during audits, whistleblower complaints, and OIG investigations — usually at the worst possible time.

Start by reviewing your referral arrangements. Map the PHI flows. Train your workforce on the overlap between fraud prevention and privacy protection. The organizations that treat these as connected problems are the ones that avoid seven-figure settlements.

Review the training resources available in our HIPAA compliance training catalog to ensure your team understands where healthcare fraud law and HIPAA intersect. Because in 2026, regulators aren't drawing lines between these two areas of law — and neither should you.