Skip to content
Behavioral Health Resource Solutionby The Vanguard Solution

Search the resource library

Search procedure codes, payer policies, state requirements and more

Compliance & Accreditation

10 Compliance Issues Behavioral Health Operators Face

The most common compliance issues in behavioral health — HIPAA, 42 CFR Part 2, billing, licensing, EKRA — who enforces each, and how facilities fix them.

Compliance Issues in Behavioral Health

Quick Facts

Category
Federal Compliance
Published
Jun 12, 2026
Reading Time
10 min

Need compliance help?

Behavioral health facilities operate under a uniquely stacked compliance burden. A single residential SUD program simultaneously answers to HIPAA and 42 CFR Part 2 on privacy, a state licensing agency on operations, an accreditor like the Joint Commission or CARF on standards, Medicaid and commercial payers on billing and documentation, and federal criminal statutes — EKRA above all — on how it fills beds. No other outpatient healthcare segment carries all five layers at once, and the layers do not coordinate: a disclosure that satisfies one rule can violate another, and an issue corrected for one auditor can resurface in the next one’s file review.

This field guide catalogs the ten compliance issues that actually surface in behavioral health — drawn from what OCR settles over, what surveyors cite, what payers claw back, and what prosecutors charge — with who flags each one and what the fix looks like. (General information, not legal advice.)

The 10 Most Common Compliance Issues in Behavioral Health

1. Privacy and confidentiality failures (HIPAA + Part 2 stacking)

What it is: Impermissible disclosures, snooping, lost unencrypted devices, missing business associate agreements, and — uniquely in SUD treatment — disclosures that pass HIPAA analysis but violate 42 CFR Part 2 ’s stricter consent rules. Who flags it: HHS Office for Civil Rights (complaints and breach investigations), state attorneys general, and accreditation surveyors reviewing information-management practices. The fix: a current security risk analysis, role-based access, BAAs with every vendor touching PHI, and dual HIPAA/Part 2 review of every disclosure pathway. For examples, penalty tiers, and enforcement cases, see our guide to HIPAA violations in behavioral health.

2. Improper consent and re-disclosure of SUD records

What it is: Sharing SUD treatment records without Part 2-compliant consent — to referral sources, family, courts, or marketing systems — or re-disclosing records received from another program without authority. The 2024 Part 2 rule aligned much of the framework with HIPAA, but consent discipline still trips programs daily. Who flags it: OCR (which now enforces Part 2 with HIPAA-aligned penalties ), plus opposing counsel the moment records surface in litigation. The fix: consent workflows built into intake and release-of-information processes, not bolted on. See 42 CFR Part 2.

3. Documentation gaps

What it is: Late or missing treatment plan reviews, unsigned notes, assessments completed outside required timeframes, group notes cloned across clients, and charts that do not reflect care actually delivered. This is the most-cited category in accreditation surveys and the predicate for billing findings. Who flags it: accreditation surveyors running tracers, state surveyors, and payer auditors. The fix: documentation timeframes enforced by workflow (due-date alerts, supervisor review queues) and a standing internal chart-audit cadence. See Joint Commission behavioral health standards for what surveyors pull.

4. Billing compliance failures

What it is: Upcoding, unbundling, billing for undocumented or unrendered services, medical-necessity failures, and billing under the wrong credential or supervision arrangement. In behavioral health, the recurring patterns are billing residential days without required documentation, group therapy billed as individual, and excessive or medically unnecessary urine drug screening — a documented federal enforcement focus in the SUD industry. Who flags it: Medicaid and MCO auditors, commercial payer special investigation units, and — when patterns look intentional — DOJ under the False Claims Act, where penalties multiply per claim. The fix: documentation-to-claim reconciliation before submission, coding audits, and a revenue cycle that surfaces exceptions. See our RCM platform for how that workflow runs.

5. Staff credentialing and training lapses

What it is: Expired licenses still on the schedule, missing background checks, no documented competency evidence, and training files that stop at orientation. Who flags it: accreditation surveyors (HR chapters), state licensing surveyors, and payer credentialing audits — and a single lapsed license can taint every claim billed under it. The fix: credential and training expiration tracking with lead-time alerts, and competency evidence tied to role. See staff training requirements.

6. State licensing violations

What it is: Operating outside licensed scope or capacity — more beds than licensed, a level of care the license doesn’t cover, satellite locations never added to the license — plus lapsed renewals and unreported ownership changes. Who flags it: state licensing agencies, often via complaint or routine survey. Consequences range from corrective plans to admission freezes and license revocation. The fix: treat the license as a living document; reconcile actual operations against licensed scope quarterly. Requirements vary sharply by state — see the state-by-state hub and our state compliance guides.

7. Patient brokering and referral-fee violations (EKRA)

What it is: Paying or receiving anything of value for patient referrals — per-admission commissions to marketers, buying leads priced per admit, paying “case managers” who deliver patients, or covering travel and rent to capture an admission. The Eliminating Kickbacks in Recovery Act ( 18 U.S.C. § 220 ↗ ) makes this a federal crime for recovery homes, clinical treatment facilities, and laboratories — covering commercial insurance, not just federal programs — with penalties of up to $200,000 and 10 years per occurrence. State laws stack on top: Florida’s Patient Brokering Act (Fla. Stat. § 817.505) is the most aggressively prosecuted. Who flags it: DOJ, state task forces, and competitors who report. The fix: compensation structures for marketing and admissions staff that never vary with admissions; counsel review of every referral relationship. This is the issue SUD operators actually get prosecuted under — and the one generic compliance guides never mention.

8. Marketing and admissions misrepresentation

What it is: Deceptive advertising — misrepresenting outcomes, masquerading directory sites, bait-and-switch admissions (“we take your insurance” when out-of-network), and undisclosed paid referrals. Who flags it: the FTC, state deceptive-practices enforcers, and Google/Meta ad platforms via LegitScript certification requirements for addiction treatment advertisers. The fix: substantiate every outcome claim, disclose relationships, and keep admissions scripts accurate about coverage and services.

9. Incident reporting failures

What it is: Sentinel events not internally reviewed, abuse and neglect allegations not reported to state authorities within mandatory windows, and incident logs that exist but never produce corrective action. Who flags it: state licensing agencies (mandatory reporting rules), accreditors (sentinel event policy expectations), and — in the worst cases — law enforcement and plaintiffs’ counsel. The fix: an incident workflow with severity triage, owner assignment, regulatory-reporting decision points with deadlines, and closure evidence.

10. Environment-of-care and safety deficiencies

What it is: Ligature risks in residential settings, medication storage failures, missed fire drills, expired emergency supplies, and unmitigated environmental hazards. Who flags it: accreditation surveyors (this is the most-cited Joint Commission findings category in behavioral health) and state surveyors. The fix: documented environmental risk assessments, scheduled safety rounds with sign-off, and remediation tracking. See the findings section of our Joint Commission guide.

Who Enforces What: The BH Compliance Map

Print this table for your next board meeting: most boards have never seen the full enforcement surface in one place.

EnforcerWhat they look atWhat an action looks like
HHS Office for Civil RightsHIPAA Privacy/Security/Breach rules; 42 CFR Part 2Investigation → settlement with corrective action plan and monitoring, or civil monetary penalties
SAMHSAPart 2 program rules; OTP certification (42 CFR Part 8)Certification action for OTPs; rulemaking and oversight
State licensing agencyLicense scope, staffing, safety, incident reportingSurvey findings → corrective plan, fines, admission freeze, suspension, revocation
Joint Commission / CARFAccreditation standards conformanceRequirements for improvement / QIP → conditional status → loss of accreditation
Medicaid / MCO auditorsClaims vs documentation, medical necessity, credentialingRecoupment, prepayment review, network termination, referral to program integrity units
DOJ / HHS-OIGFalse Claims Act, EKRA, anti-kickbackCivil settlements, criminal prosecution, exclusion from federal programs
FTC / state AGsMarketing claims, deceptive practices, privacyConsent orders, civil penalties, injunctions

Building a Compliance Program That Catches Issues Early

The structure regulators expect is not mysterious — HHS-OIG has published compliance program guidance for decades, and its General Compliance Program Guidance ↗ lays out seven elements:

For a mid-size behavioral health organization, the practical core is the rhythm: an annual risk assessment that ranks the ten issues above for your programs, a rolling internal audit calendar (chart audits monthly, billing reconciliation quarterly, credential sweep monthly, environment rounds weekly), and a compliance committee that reviews findings and closes corrective actions on the record. A program that exists on paper but produces no findings is itself a red flag to auditors — real programs find things.

When a finding does surface, the response sequence matters as much as the finding: contain it, document the facts while they are fresh, assess whether any external reporting clock is running (breach notification, state incident reporting, payer self-disclosure), correct the root cause rather than the instance, and record the closure. Regulators consistently treat documented self-correction as mitigation — and treat the same issue found by them after you knew about it as willful neglect.

  • Written policies and procedures
  • A designated compliance officer and committee with real authority
  • Training and education on a defined cadence
  • Effective lines of communication, including anonymous reporting
  • Internal monitoring and auditing
  • Enforced disciplinary standards, applied consistently
  • Prompt response and corrective action when issues surface

How Software Surfaces Compliance Issues Before Auditors Do

Most of the ten issues above are detectable in data long before an auditor arrives: a treatment plan review that is 12 days overdue, a license expiring in 30 days, a claim about to go out against an unsigned note, an incident report with no corrective action after 60 days. Software that runs these checks continuously turns compliance from an annual scramble into a standing dashboard — documentation due-date alerts, credential and training expiry tracking, claim-to-documentation checks, incident workflow with closure evidence, audit logs on every record access, and outcomes reporting for accreditation performance measurement.

That is the design philosophy behind the platform: the EHR keeps clinical documentation and training evidence continuously survey-ready, and the RCM platform keeps claims tied to the documentation behind them.

Sources

Want the compliance dashboard instead of the scramble? Request a demo to see how surfaces issues before auditors do.

This guide is provided for informational purposes only and does not constitute legal, regulatory, or professional advice. Regulations change frequently — always verify current requirements with the relevant state agency or accrediting body. is not a law firm or consulting firm.

See a Compliance-Ready EHR

helps behavioral health organizations navigate compliance with confidence.

Reference tables

EnforcerWhat they look atWhat an action looks like
HHS Office for Civil RightsHIPAA Privacy/Security/Breach rules; 42 CFR Part 2Investigation → settlement with corrective action plan and monitoring, or civil monetary penalties
SAMHSAPart 2 program rules; OTP certification (42 CFR Part 8)Certification action for OTPs; rulemaking and oversight
State licensing agencyLicense scope, staffing, safety, incident reportingSurvey findings → corrective plan, fines, admission freeze, suspension, revocation
Joint Commission / CARFAccreditation standards conformanceRequirements for improvement / QIP → conditional status → loss of accreditation
Medicaid / MCO auditorsClaims vs documentation, medical necessity, credentialingRecoupment, prepayment review, network termination, referral to program integrity units
DOJ / HHS-OIGFalse Claims Act, EKRA, anti-kickbackCivil settlements, criminal prosecution, exclusion from federal programs
FTC / state AGsMarketing claims, deceptive practices, privacyConsent orders, civil penalties, injunctions

Common questions

Official sources

1,465 words · reviewed 2026-06-12
10 Compliance Issues Behavioral Health Operators Face — The Behavioral Health Resource Solution