Practical knowledge from people who do the work.
Medical billing, coding, denials, credentialing, PCMH and practice operations, written to be useful on Monday morning.
Payer Audit Records Requests: Answering a TPE or SIU Letter for 20 Charts
A letter arrives asking for 20 medical records within 45 days. Whether it comes from a Medicare contractor running Targeted Probe and Educate or a commercial plan's special investigations unit, the next six weeks decide whether this ends in education or in recoupment. Here is how we handle payer audit records requests.
Which Vendors Need a HIPAA Business Associate Agreement, and Which Do Not
Every practice has a drawer of business associate agreements and a longer list of vendors that never signed one. What makes a vendor a business associate, twenty common vendors sorted into yes and no, the terms the contract must contain and a two-week inventory plan.
MIPS 2025 Data Submission Closes March 31, 2026: A Four-Week Checklist
The submission window for the 2025 MIPS performance year closes at 8 pm Eastern on March 31, 2026. Here is what to verify in the QPP portal this month, the numbers that decide whether you clear the 75-point threshold, and the mistakes that cost practices a 9 percent cut in 2027.
When to Use an ABN: Advance Beneficiary Notice Rules for Medical Practices
The Advance Beneficiary Notice is the only way to bill a Medicare patient for a service Medicare denies as not reasonable and necessary, and most practices use it wrong in both directions. We explain when to use an ABN, when not to, how to fill it in, the GA and GX modifiers, and the 2026 form version question.
A $103,000 Phishing Settlement and the HIPAA Risk Analysis for a Small Practice
On February 19, 2026, OCR settled with an Illinois treatment center for $103,000 after a phishing attack exposed 1,980 patients' records. The finding was not the phishing. It was the missing risk analysis. Here is what the settlement requires, and how a small practice performs the analysis OCR keeps asking for.
The HIPAA Security Rule Update Is Still a Proposal: What to Do While You Wait
HHS proposed the first major rewrite of the HIPAA Security Rule on January 6, 2025. Thirteen months later it is still not final, provider groups have asked for it to be scaled back, and OCR is enforcing the existing rule aggressively. Here is what the proposal would require and what to do now.
2025 Healthcare Data Breaches: 710 Large Breaches and What Practices Should Do
The 2025 numbers are in: 710 breaches of 500 or more records reported to OCR, 61.5 million people affected, and providers accounting for more than half of the incidents. We read the year-end report for what it says about practices your size, and list the controls that would have stopped most of it.
Medicaid Work Requirements Arrive in 2027: What Practices Should Set Up Now
The July 2025 reconciliation law requires states to apply an 80-hour monthly work requirement to Medicaid expansion adults by January 1, 2027, with six-month redeterminations. CMS issued initial guidance in December and owes a rule by June 1. Here is what changes for practices and what to do now.
MIPS 2025 Submission Is Open: A Twelve-Week Plan to Get Data In Before March 31
The 2025 MIPS performance year submission window opened January 2 and closes March 31, 2026 at 8 p.m. Eastern. Here is how we sequence the work: eligibility checks, quality measure completeness, promoting interoperability attestations and improvement activities.
Page 4 of 6 · 46 articles
Want this level of attention on your own revenue cycle?
The same people who write these articles run billing, coding, denial management and credentialing for practices nationwide.