Dorsey Health Law
New State-Level Anti-Kickback Statute Expands Minnesota AG’s Power to Prosecute Healthcare Fraud
On May 23, 2025, Minnesota Governor Tim Walz signed the Human Services omnibus policy bill into law, which included in part, the addition of a new statutory provision in the state’s criminal code, Chapter 609. Effective August 1, 2025, Section 609.542 of the Minnesota Statutes will essentially inscribe the federal Anti-Kickback Statute (United States Code, title 42, section 1320a-7b(b)) into state law, so that state prosecutors may address fraud against Human Services programs, including without limitation, the state Medical Assistance and Child Care Assistance programs as well as state-funded substance use disorder treatment programs. The new statute makes it a crime for an individual or entity to “intentionally” solicit, receive, offer, or provide “money, a discount, a credit, a waiver, a rebate, a good, a service, employment, or anything else of value” in exchange for (i) referring another individual for the furnishing or arranging to furnish any item or service; (ii) purchasing, leasing, ordering, or arranging for or recommending purchasing, leasing or ordering any good, facility, service, or item; or (iii) applying for or receiving any item or service which is payable in whole or in part under a federal health care program (as defined in United States Code, title 42, section 1320a-7b(f), including without limitation Medicare, Medicaid, and TRICARE), state behavioral health program (see Chapter 254B of the Minnesota Statutes), or state child care assistance program (see Chapter 142E of the Minnesota Statutes). Like the federal analog, a violation of the state-level anti-kickback statute constitutes a false or fraudulent claim for purposes of the state-level false claims act (see Section 15C.02 of the Minnesota Statutes). But, at the same time, the same exceptions, or Safe Harbors, to the federal Anti-Kickback Statute also apply to Chapter 609.542. In addition to the adoption of the federal Safe Harbors, the statute adds an exception for employers enrolled in the Child Care Assistance program. The new statute does not apply to payment from an employer to an employee who provides covered items or services under Chapter 142E in the scope of their employment or to childcare provider discounts, scholarships, or to other financial assistance to families allowable under Section 142E.17, subdivision 7 of the Minnesota Statutes. The criminal sentence for a violation of this statute varies depending on the value of the kickback at issue. For a kickback that is not more than $5,000, the sentence may include imprisonment for not more than five years or payment of a fine of not more than $10,000, or both. For a kickback that is more than $5,000 and not more than $35,000, the sentence may include imprisonment of not more than ten years or payment of a fine of not more than $20,000, or both. And for a kickback that exceeds $35,000, the sentence may include imprisonment of not more than 20 years or payment of a fine of not more than $100,000, or both. The dollar amounts of any kickbacks provided within a six-month period may be aggregated for the purposes of charging and sentencing under this statute. In comparison, criminal penalties for a violation of the federal Anti-Kickback Statute may include imprisonment of not more than ten years or payment of a fine not more than $100,000, or both. The federal statute does not discuss aggregation of claims. But note that a violation of the federal Anti-Kickback Statute may also be subject to civil monetary penalties up to $50,000 per kickback plus three times the amount of the kickback (also known as treble damages). The new Minnesota statute does not contemplate the collection of state-level civil monetary penalties in connection with a violation of Chapter 609.542. We note, however, that pursuant to Section 62J.23 of the Minnesota Statutes, the state commissioner of health separately may levy a fine against any individual or entity that violates the federal Anti-Kickback Statute in the amount of $1,000 or 110 percent of the estimated kickback, whichever is greater. Legislative Background Section 609.542 appears to be, at least in part, a direct reaction to the recent indictment of Evergreen Recovery and the recent $18.5 million settlement between the United States Department of Justice and NUWAY Alliance. Both Evergreen and NUWAY are substance use disorder treatment program providers in Minnesota that allegedly provided free or subsidized housing for patients in exchange for patients’ attendance at counseling sessions payable by federal healthcare programs. These state investigations serve as a good reminder that prosecutable kickbacks do not always take the form of cash, but can be anything of value, including discounted or in-kind services. Expected Impact Unlike state-level anti-kickback statutes in other states and unlike Section 62J.23 (discussed above), the new Minnesota statute notably does not expand the scope of state kickback enforcement to commercial arrangements. The expected impact of this statute is that, as of August 1, 2025, state prosecutors will be able to file anti-kickback claims that previously were the purview of only federal prosecutors and may ask for additional jail time (20 years instead of ten years) during sentencing for violations. We will have to wait for additional guidance, or new enforcement actions, to fully understand how broadly Minnesota prosecutors and, ultimately, the courts will interpret the mens rea term “intentionally,” as it is used in Chapter 609.542. If a violation of the state statute merely requires intentional action, rather than intentional wrongful action, the requisite mens rea under the state-level anti-kickback statute may be a lower threshold than under the federal Anti-Kickback Statute.[1] Overall, it remains to be seen whether this new statute will indeed significantly increase healthcare fraud enforcement in Minnesota, particularly against individuals and entities that do business with the state. Please contact the authors or your regular Dorsey attorney with any questions about how this new statute could affect your current or contemplated business practices. [1] At least under Eighth Circuit precedent. There currently is a significant federal Circuit split regarding the requisite mens rea under the Anti-Kickback Statute.
July 22, 2025
FTC Takes First Enforcement Action for Violation of the Health Breach Notification Rule – A Federal Health Privacy Rule Beyond HIPAA
On February 1, 2023, the Federal Trade Commission (FTC) filed a complaint in the U.S. District Court for the Northern District of California alleging that digital health platform GoodRx violated the FTC Act by repeatedly sharing personal health information with advertising companies and platforms, such as Facebook and Google, and failed to report the unauthorized disclosures pursuant to its Health Breach Notification Rule (16 C.F.R. § 318). Though GoodRx maintains that it shared all health information appropriately, according to the proposed stipulated order, the digital health platform has agreed to pay a $1.5 million civil penalty. Once the proposed order is approved by a federal court judge, the monetary penalty, as well as several non-monetary sanctions, will go into effect. This settlement may signal the beginning of a new era of health privacy enforcement, where the Health Insurance Portability and Accountability Act of 1996 (HIPAA) is not the only federal health privacy law for which organizations must ensure compliance. The FTC’s Health Breach Notification Rule is not new—even though the GoodRx complaint marks its first enforcement action. The rule went into effect in September 2009 and was the subject of a 2021 FTC policy statement. Substantively, the Health Breach Notification Rule is very similar to HIPAA’s Breach Notification Rule (45 C.F.R. §§ 164.400-414). Pursuant to both rules, a data holder must notify the subject of any unsecured “individually identifiable health information” and the agency responsible for enforcing the applicable rule in response to a breach of such information. Also pursuant to both rules, if a breach of unsecured personal health information involves more than 500 individuals (and, in the case of the Health Breach Notification Rule, if a breach involves exactly 500 individuals), the data holder must notify the media. The primary differentiating factor between the rules are the types of entities to which they apply. The HIPAA Breach Notification Rule is specific in scope and only applies to Covered Entities and their Business Associates. A Covered Entity is limited to a: (1) health plan, (2) health care clearinghouse, or (3) health care provider, who also electronically transmits health information in connection with transactions for which HHS has adopted standards. A Business Associate is a person or entity who, on behalf of a Covered Entity, performs or assists in performance of a function or activity involving the use or disclosure of individually identifiable health information. The FTC’s Health Breach Notification Rule is broader in scope and applies to all vendors that “offer or maintain a personal health record (PHR).” A PHR is an electronic record of “individually identifiable health information,” as defined in section 1171(6) of the Social Security Act (42 U.S.C. 1320d(6)), that can be drawn from multiple sources and that is managed, shared, and controlled by or primarily for the individual. The FTC has stated that an example PHR Vendor might be a health app that collects information from consumers and can sync with a consumer’s fitness tracker. The Health Breach Notification Rule also applies to “PHR related entities” and “third-party service providers.” A PHR Related Entity interacts with a PHR Vendor by either offering products or services through the Vendor’s website, offering products or services through a Covered Entity’s website that offers individual’s health records, or by accessing information in a PHR or sending information to a PHR. The FTC states that an example of a PHR Related Entity might be a company that offers a fitness tracker and sends information to health apps. A Third Party Service Provider is an entity that provides services to a PHR Vendor in connection with the offering or maintenance of a PHR or to a PHR Related Entity in connection with a product or service offered by that entity; and accesses, maintains, retains, modifies, records, stores, destroys, or otherwise holds, uses, or discloses unsecured PHR identifiable health information as a result of such services. The FTC states that an example of a Third Party Service Provider might be a company that provides billing, debt collection, or data storage services relating to health information for a PHR. In light of the GoodRx complaint and the FTC’s enforcement of the Health Breach Notification Rule, all entities that utilize or maintain personal health information—and especially those offering healthcare apps, connected devices, and wearables, that often do not fall under the definitions of Covered Entities and Business Associates—should evaluate the applicability of the Health Breach Notification Rule to their organization and its business practices. Entities that fall under the definitions of PHR Vendor, PHR Related Entity, and Third Party Service Provider, should be sure to have an effective privacy and security program in place, including procedures for conducting regular risk assessments and risk management trainings to ensure proper identification of and response to a breach of personal health information. Such entities should also review their privacy policies, both internally and externally-facing, to ensure they reflect current data-sharing practices, and should review their vendor contracts to take inventory of any permissions or restrictions on how personal health information is used and disclosed to ensure they are obtaining the necessary consent. For more information on the Health Breach Notification Rule, the FTC’s Health Privacy webpage offers a variety of resources—including a simplified explainer of the rule, compliance tips, and an interactive tool geared toward mobile health apps. For more tailored guidance, or with any questions, please do not hesitate to reach out to one of the authors or your regular Dorsey & Whitney attorney.
February 15, 2023

