10 Compliance Issues Behavioral Health Operators Face
The most common compliance issues in behavioral health — HIPAA, 42 CFR Part 2, billing, licensing, EKRA — who enforces each, and how facilities fix them.
Compliance Issues in Behavioral Health
Quick Facts
- Category
- Federal Compliance
- Published
- Jun 12, 2026
- Reading Time
- 10 min
Need compliance help?
Behavioral health facilities operate under a uniquely stacked compliance burden. A single residential SUD program simultaneously answers to HIPAA and 42 CFR Part 2 on privacy, a state licensing agency on operations, an accreditor like the Joint Commission or CARF on standards, Medicaid and commercial payers on billing and documentation, and federal criminal statutes — EKRA above all — on how it fills beds. No other outpatient healthcare segment carries all five layers at once, and the layers do not coordinate: a disclosure that satisfies one rule can violate another, and an issue corrected for one auditor can resurface in the next one’s file review.
This field guide catalogs the ten compliance issues that actually surface in behavioral health — drawn from what OCR settles over, what surveyors cite, what payers claw back, and what prosecutors charge — with who flags each one and what the fix looks like. (General information, not legal advice.)
The 10 Most Common Compliance Issues in Behavioral Health
1. Privacy and confidentiality failures (HIPAA + Part 2 stacking)
What it is: Impermissible disclosures, snooping, lost unencrypted devices, missing business associate agreements, and — uniquely in SUD treatment — disclosures that pass HIPAA analysis but violate 42 CFR Part 2 ’s stricter consent rules. Who flags it: HHS Office for Civil Rights (complaints and breach investigations), state attorneys general, and accreditation surveyors reviewing information-management practices. The fix: a current security risk analysis, role-based access, BAAs with every vendor touching PHI, and dual HIPAA/Part 2 review of every disclosure pathway. For examples, penalty tiers, and enforcement cases, see our guide to HIPAA violations in behavioral health.
2. Improper consent and re-disclosure of SUD records
What it is: Sharing SUD treatment records without Part 2-compliant consent — to referral sources, family, courts, or marketing systems — or re-disclosing records received from another program without authority. The 2024 Part 2 rule aligned much of the framework with HIPAA, but consent discipline still trips programs daily. Who flags it: OCR (which now enforces Part 2 with HIPAA-aligned penalties ), plus opposing counsel the moment records surface in litigation. The fix: consent workflows built into intake and release-of-information processes, not bolted on. See 42 CFR Part 2.
3. Documentation gaps
What it is: Late or missing treatment plan reviews, unsigned notes, assessments completed outside required timeframes, group notes cloned across clients, and charts that do not reflect care actually delivered. This is the most-cited category in accreditation surveys and the predicate for billing findings. Who flags it: accreditation surveyors running tracers, state surveyors, and payer auditors. The fix: documentation timeframes enforced by workflow (due-date alerts, supervisor review queues) and a standing internal chart-audit cadence. See Joint Commission behavioral health standards for what surveyors pull.
4. Billing compliance failures
What it is: Upcoding, unbundling, billing for undocumented or unrendered services, medical-necessity failures, and billing under the wrong credential or supervision arrangement. In behavioral health, the recurring patterns are billing residential days without required documentation, group therapy billed as individual, and excessive or medically unnecessary urine drug screening — a documented federal enforcement focus in the SUD industry. Who flags it: Medicaid and MCO auditors, commercial payer special investigation units, and — when patterns look intentional — DOJ under the False Claims Act, where penalties multiply per claim. The fix: documentation-to-claim reconciliation before submission, coding audits, and a revenue cycle that surfaces exceptions. See our RCM platform for how that workflow runs.
5. Staff credentialing and training lapses
What it is: Expired licenses still on the schedule, missing background checks, no documented competency evidence, and training files that stop at orientation. Who flags it: accreditation surveyors (HR chapters), state licensing surveyors, and payer credentialing audits — and a single lapsed license can taint every claim billed under it. The fix: credential and training expiration tracking with lead-time alerts, and competency evidence tied to role. See staff training requirements.
6. State licensing violations
What it is: Operating outside licensed scope or capacity — more beds than licensed, a level of care the license doesn’t cover, satellite locations never added to the license — plus lapsed renewals and unreported ownership changes. Who flags it: state licensing agencies, often via complaint or routine survey. Consequences range from corrective plans to admission freezes and license revocation. The fix: treat the license as a living document; reconcile actual operations against licensed scope quarterly. Requirements vary sharply by state — see the state-by-state hub and our state compliance guides.
7. Patient brokering and referral-fee violations (EKRA)
What it is: Paying or receiving anything of value for patient referrals — per-admission commissions to marketers, buying leads priced per admit, paying “case managers” who deliver patients, or covering travel and rent to capture an admission. The Eliminating Kickbacks in Recovery Act ( 18 U.S.C. § 220 ↗ ) makes this a federal crime for recovery homes, clinical treatment facilities, and laboratories — covering commercial insurance, not just federal programs — with penalties of up to $200,000 and 10 years per occurrence. State laws stack on top: Florida’s Patient Brokering Act (Fla. Stat. § 817.505) is the most aggressively prosecuted. Who flags it: DOJ, state task forces, and competitors who report. The fix: compensation structures for marketing and admissions staff that never vary with admissions; counsel review of every referral relationship. This is the issue SUD operators actually get prosecuted under — and the one generic compliance guides never mention.
8. Marketing and admissions misrepresentation
What it is: Deceptive advertising — misrepresenting outcomes, masquerading directory sites, bait-and-switch admissions (“we take your insurance” when out-of-network), and undisclosed paid referrals. Who flags it: the FTC, state deceptive-practices enforcers, and Google/Meta ad platforms via LegitScript certification requirements for addiction treatment advertisers. The fix: substantiate every outcome claim, disclose relationships, and keep admissions scripts accurate about coverage and services.
9. Incident reporting failures
What it is: Sentinel events not internally reviewed, abuse and neglect allegations not reported to state authorities within mandatory windows, and incident logs that exist but never produce corrective action. Who flags it: state licensing agencies (mandatory reporting rules), accreditors (sentinel event policy expectations), and — in the worst cases — law enforcement and plaintiffs’ counsel. The fix: an incident workflow with severity triage, owner assignment, regulatory-reporting decision points with deadlines, and closure evidence.
10. Environment-of-care and safety deficiencies
What it is: Ligature risks in residential settings, medication storage failures, missed fire drills, expired emergency supplies, and unmitigated environmental hazards. Who flags it: accreditation surveyors (this is the most-cited Joint Commission findings category in behavioral health) and state surveyors. The fix: documented environmental risk assessments, scheduled safety rounds with sign-off, and remediation tracking. See the findings section of our Joint Commission guide.
Who Enforces What: The BH Compliance Map
Print this table for your next board meeting: most boards have never seen the full enforcement surface in one place.
| Enforcer | What they look at | What an action looks like |
|---|---|---|
| HHS Office for Civil Rights | HIPAA Privacy/Security/Breach rules; 42 CFR Part 2 | Investigation → settlement with corrective action plan and monitoring, or civil monetary penalties |
| SAMHSA | Part 2 program rules; OTP certification (42 CFR Part 8) | Certification action for OTPs; rulemaking and oversight |
| State licensing agency | License scope, staffing, safety, incident reporting | Survey findings → corrective plan, fines, admission freeze, suspension, revocation |
| Joint Commission / CARF | Accreditation standards conformance | Requirements for improvement / QIP → conditional status → loss of accreditation |
| Medicaid / MCO auditors | Claims vs documentation, medical necessity, credentialing | Recoupment, prepayment review, network termination, referral to program integrity units |
| DOJ / HHS-OIG | False Claims Act, EKRA, anti-kickback | Civil settlements, criminal prosecution, exclusion from federal programs |
| FTC / state AGs | Marketing claims, deceptive practices, privacy | Consent orders, civil penalties, injunctions |
Building a Compliance Program That Catches Issues Early
The structure regulators expect is not mysterious — HHS-OIG has published compliance program guidance for decades, and its General Compliance Program Guidance ↗ lays out seven elements:
For a mid-size behavioral health organization, the practical core is the rhythm: an annual risk assessment that ranks the ten issues above for your programs, a rolling internal audit calendar (chart audits monthly, billing reconciliation quarterly, credential sweep monthly, environment rounds weekly), and a compliance committee that reviews findings and closes corrective actions on the record. A program that exists on paper but produces no findings is itself a red flag to auditors — real programs find things.
When a finding does surface, the response sequence matters as much as the finding: contain it, document the facts while they are fresh, assess whether any external reporting clock is running (breach notification, state incident reporting, payer self-disclosure), correct the root cause rather than the instance, and record the closure. Regulators consistently treat documented self-correction as mitigation — and treat the same issue found by them after you knew about it as willful neglect.
- Written policies and procedures
- A designated compliance officer and committee with real authority
- Training and education on a defined cadence
- Effective lines of communication, including anonymous reporting
- Internal monitoring and auditing
- Enforced disciplinary standards, applied consistently
- Prompt response and corrective action when issues surface
How Software Surfaces Compliance Issues Before Auditors Do
Most of the ten issues above are detectable in data long before an auditor arrives: a treatment plan review that is 12 days overdue, a license expiring in 30 days, a claim about to go out against an unsigned note, an incident report with no corrective action after 60 days. Software that runs these checks continuously turns compliance from an annual scramble into a standing dashboard — documentation due-date alerts, credential and training expiry tracking, claim-to-documentation checks, incident workflow with closure evidence, audit logs on every record access, and outcomes reporting for accreditation performance measurement.
That is the design philosophy behind the platform: the EHR keeps clinical documentation and training evidence continuously survey-ready, and the RCM platform keeps claims tied to the documentation behind them.
Sources
Want the compliance dashboard instead of the scramble? Request a demo to see how surfaces issues before auditors do.
This guide is provided for informational purposes only and does not constitute legal, regulatory, or professional advice. Regulations change frequently — always verify current requirements with the relevant state agency or accrediting body. is not a law firm or consulting firm.
See a Compliance-Ready EHR
helps behavioral health organizations navigate compliance with confidence.
Reference tables
| Enforcer | What they look at | What an action looks like |
|---|---|---|
| HHS Office for Civil Rights | HIPAA Privacy/Security/Breach rules; 42 CFR Part 2 | Investigation → settlement with corrective action plan and monitoring, or civil monetary penalties |
| SAMHSA | Part 2 program rules; OTP certification (42 CFR Part 8) | Certification action for OTPs; rulemaking and oversight |
| State licensing agency | License scope, staffing, safety, incident reporting | Survey findings → corrective plan, fines, admission freeze, suspension, revocation |
| Joint Commission / CARF | Accreditation standards conformance | Requirements for improvement / QIP → conditional status → loss of accreditation |
| Medicaid / MCO auditors | Claims vs documentation, medical necessity, credentialing | Recoupment, prepayment review, network termination, referral to program integrity units |
| DOJ / HHS-OIG | False Claims Act, EKRA, anti-kickback | Civil settlements, criminal prosecution, exclusion from federal programs |
| FTC / state AGs | Marketing claims, deceptive practices, privacy | Consent orders, civil penalties, injunctions |
Common questions
Official sources
- General Compliance Program Guidanceoig.hhs.gov
- HHS OCR HIPAA enforcementhhs.gov
- eCFR 42 CFR Part 2ecfr.gov
- The Joint Commissionjointcommission.org
- CARF Internationalcarf.org