Dorsey Health Law
Healthcare Fraud and Abuse
The False Claims Act and the Anti-Kickback Statute: Causation, Materiality, and the Connection Between the Two
Violations of the federal Anti-Kickback Statute (the “AKS”)[1] have long served as a basis for liability under the federal False Claims Act (the “FCA”).[2] Recently, however, there has been increasing uncertainty regarding how far a violation of the AKS sweeps to render claims “false” under the FCA. Courts are currently at odds with each other regarding the appropriate causation standard—how directly an AKS violation must cause submission of a claim—in order for that claim to be false under the FCA. Because FCA defendants are liable for up to treble damages, plus substantial fines and penalties, for every false claim, this current state of flux has significant implications for the scope of damages in FCA cases predicated on violations of the AKS. In its 2016 decision in Universal Health Services v. United States ex rel. Escobar, the U.S. Supreme Court confirmed that a defendant could be liable under the FCA for what are commonly referred to as “legally false” claims; or, claims that, despite being factually accurate, are rendered false due to an underlying non-compliance with law that is material to the government’s decision to pay a claim.[3] In the healthcare industry, non-compliance with the AKS became a quintessential predicate for FCA liability, with courts accepting that compliance with the AKS is material to the government’s decision to pay a claim. Less settled, however, was the requisite nexus between the AKS violation and a given claim for the claim to be considered false. Some courts have accepted a broad “taint theory,” under which the entire relationship between two parties is considered tainted by a violation of the AKS. Under this theory, any claim for services referred between the parties would be grounds for liability under the FCA. Other courts have required that the AKS violation touch, with differing degrees of directness, the claims at issue. In such cases, an FCA defendant would be liable only for claims that had the requisite degree of connectedness to an AKS violation. Then, in 2010, the Affordable Care Act codified in statute (the “ACA Amendment”) that a claim that includes items or services “resulting from” an AKS violation constitutes a false or fraudulent claim under the FCA.[4] This “resulting from” language has proven to be a major point of disagreement among courts, creating significant confusion regarding whether and to what extent an AKS violation must cause submission of a claim in order for such submission to violate the FCA. To further complicate matters, courts have far from settled the question of whether the same causation standard applies whether or not the government relies on the ACA Amendment’s per se falsity to plead that a defendant violated the FCA. This is to say that it remains largely unsettled whether the causation standard that applies to pleadings that invoke the ACA Amendment also apply where the government instead (or also) invokes Escobar and pleads that compliance with the AKS is material to the government’s decision to pay a claim. So, what standard applies? Currently, it depends on the court. The Third Circuit has held that the ACA Amendment requires only some “link” or “connection” between the alleged kickback and the subsequent claims. In S. ex rel. Greenfield v. Medco Health Sols., Inc.[5], the court acknowledged that the Supreme Court had previously interpreted the plain meaning of the nearly identical phrase “results from” in the context of the Controlled Substances Act as requiring actual, or but-for causation.[6] However, without stating whether the plain meaning of “resulting from” was unclear, the court looked to legislative intent, finding that such a strict causation requirement would require proof that a kickback “actually influenced a patient’s or medical professional’s judgment,” which would be inconsistent with Congress’ apparent intentions to reach a “broad swath” of fraud and abuse.[7] The Sixth and Eighth Circuits have adopted a strict but-for causation standard, requiring that the government establish that the items or services would not have been submitted for payment if not for the AKS violation.[8] In Cairns, the court asserted that the “resulting from” language in the ACA Amendment is “unambiguously causal”, requiring but-for causation in accordance with the Supreme Court’s holding in Burrage.[9] Acknowledging that the Third Circuit came out differently on this issue in Greenfield, the court in Cairns rejected the Third Circuit’s approach, stressing that when the plain meaning of a term or phrase is unambiguous, review of legislative history is improper. The court further noted that it is not enough for the government to show that the defendant failed to disclose the AKS violation when submitting the claims at issue.[10] In S. ex rel. Fesenmaier v. Cameron-Ehlen Grp., Inc., the U.S. District Court for the District of Minnesota clarified that, under Cairns, but-for causation only applies to claims that rely on the ACA Amendment to show falsity.[11] Conversely, where the government had pled that compliance with the AKS was material to a decision to pay the claim, the District Court required that the government show only proximate causation (established if the misconduct was a substantial factor in submission of the claims and such submission was reasonably foreseeable or anticipated as a natural consequence of the misconduct).[12] In a seemingly contradictory opinion, the U.S. District Court for the District of Minnesota in S. ex rel. Louderback v. Sunovion Pharms., Inc. held that a plaintiff may not establish FCA liability premised on a violation of the AKS by simply showing that compliance with the AKS was material to the government’s decision to pay the claim (which, under Fesenmaier, requires only proximate causation).[13] In other words, a plaintiff must meet the ACA Amendment but-for causation standard. This holding is similar to the Sixth Circuit’s holding in Cairns, which also found that but-for causation is required to establish FCA liability on the basis of a violation of the AKS (although query whether the Sixth Circuit intended to limit this holding to pleadings that rely on the ACA Amendment). In the First Circuit, the U.S. District Court for the District of Massachusetts has created conflicting case law. In S. v. Regeneron Pharms. Inc. the court mixed concepts, creating an FCA causation standard that starts to merge with notions of intent under the AKS. While the court purportedly adopted the but-for causation standard from Cairns, it then stated that an AKS violation need only be a “substantial factor” in causing referrals, rather than the sole cause, in order for claims resulting from such referrals to be false.[14] Conversely, in U.S. v. Teva Pharms. USA, Inc., the court held that only a “sufficient causal connection” must exist between the AKS violation and a claim in order to render the claim false under the FCA.[15] As a result of these conflicting holdings, the causation standard issue is now under interlocutory appeal with the First Circuit.[16] In addition to being determinative of whether a violation of the FCA occurred at all, a court’s view of the appropriate causation standard can have a significant effect on the scope of damages. If but-for causation is required, the number of affected claims will likely be limited to those claims for which there is evidence that the item or service would not have been referred absent the AKS violation. At the other end of the spectrum, where there is no requirement to show any sort of causal connection between the alleged violation of the AKS and the submission of a purportedly-false claim, damages can grow to include any claim for an item or service referred between parties whose relationship can be said to be “tainted” by a violation of the AKS. In light of the FCA’s liability scheme—which includes treble damages and significant per-claim fines and penalties—the unsettled nature of this causation requirement can lead to significant uncertainty regarding a defendant’s potential exposure in FCA cases. Defendants facing allegations that they are liable under the FCA as a result of non-compliance with the AKS may see potential damages balloon if courts loosen causation requirements. If courts impose stricter causation requirements, on the other hand, the government may find it harder and harder to achieve the mammoth judgments and settlements that we have seen in the past. [1] 42 U.S.C. § 1320a-7b(b). The Anti-Kickback Statute imposes criminal liability upon any person who knowingly and willfully solicits or receives remuneration (i.e., anything of value) in return for, or offers or pays any remuneration to induce, the referrals of items or services for which payment may be made in whole or in part under a federal health care program, including Medicare and Medicaid. [2] 31 U.S.C. §§ 3729-3733. The civil False Claims Act imposes liability upon any person who knowingly submits, or causes to submit, false or fraudulent claims to the government. [3] Universal Health Servs. v. United States ex rel. Escobar, 136 S. Ct. 1989 (2016) (noting that the FCA is not a “vehicle for punishing garden-variety breaches”, and emphasizing the importance of the government’s conduct in determining whether a particular AKS violation was material to the government’s decision to pay the claims). [4] 42 U.S.C. § 1320a-7b(g). [5] U.S. ex rel. Greenfield v. Medco Health Sols., Inc., 880 F.3d 89 (3rd Cir. 2018). [6] See Burrage v. U.S., 134 S. Ct. 881, 887-88 (2014). [7] Id. at 96-97. [8] See U.S. ex rel. Martin v. Hathaway, 63 F.4th 1043 (6th Cir. 2023), cert. denied, 144 S. Ct. 224 (2023); U.S. ex rel. Cairns v. D.S. Med. LLC, 42 F.4th 828 (8th Cir. 2022). [9] Cairns, 42 F. 4th at 834-36. [10] Cairns, 42 F.4th at 834. [11] U.S. ex rel. Fesenmaier v. Cameron-Ehlen Grp., Inc., No. 13-CV-3003, 2024 U.S. Dist. LEXIS 21897, at *8-9 (D. Minn. Feb. 8, 2024). This case is currently on appeal to the Eighth Circuit. [12] Id. at *10, 29 (noting that it was insufficient, by itself, to establish that the claims were submitted within one year of the alleged kickback). [13] No. 17-CV-1719, 2023 U.S. Dist. LEXIS 209990 (D. Minn. Nov. 27, 2023). [14] U.S. v. Regeneron Pharms., Inc., No. 20-11217-FDS, 2023 U.S. Dist. LEXIS 172618, at *31-34 (D. Mass. Sept. 27, 2023) (indicating that it would be sufficient to show that the defendant was giving copay assistance because it knew that patients would not fill prescriptions and/or physicians would not write prescriptions if such copay assistance were unavailable). [15] See U.S. v. Teva Pharms. USA, Inc., No. 20-11548-NMG, 2023 U.S. Dist. LEXIS 122272 (D. Mass. July 14, 2023). [16] See U.S. v. Regeneron Pharms., Inc., No. 20-11217-FDS, 2023 U.S. Dist. LEXIS 191418 (D. Mass. Oct. 25, 2023); U.S. v. Regeneron Pharms., Inc., No. 23-8046, 2023 U.S. App. LEXIS 33107 (1st Cir. Dec. 11, 2023).
July 11, 2024
Tracking Online User Activity: HIPAA and Other Legal Risks
The use of tracking technologies on websites and mobile applications (e.g., cookies) has become largely ubiquitous in our technology-driven world. Health care providers and organizations, for example, may use tracking technologies to identify their patients’ care needs and improve patient experience. As the use of tracking technologies burgeons, so do concerns from individuals about how to protect their personal information. Understandably so, as this technology comes with significant risks if collected information ends up in the wrong hands. Further, because of the sensitivity of the information involved, entities that handle Protected Health Information (“PHI”) and are regulated by the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) must be particularly cautious when using tracking technologies. On December 1, 2022, the Office of Civil Rights (“OCR”) at the U.S. Department of Health and Human Services (“HHS”), which is responsible for enforcing HIPAA, issued a Bulletin addressing the use of tracking technologies by regulated entities, including Covered Entities and Business Associates, as defined by HIPAA.[1] The Bulletin does not create new obligations for HIPAA-regulated entities, and seeks only to clarify current HIPAA obligations as it relates to the use of tracking technologies, specifically, when a third-party vendor is utilized. What is a Tracking Technology? A tracking technology is a “script or code” on a website or mobile application (“app”) that collects information about users as they interact with the website or application.[2] The information gathered is analyzed and used to “create insights about users’ online activities”, and even their personal characteristics, wants or needs.[3] Tracking technologies include mechanisms such as cookies, pixels, web beacons, and embedded tracking codes in apps and devices. One such example is the Facebook pixel by Meta, which website owners can embed into their website to track site visits and user activity on the website.[4] How is HIPAA Implicated? HIPAA-regulated entities are required to safeguard PHI, which includes protecting it from impermissible disclosures. When regulated entities utilize third-party vendors to track the activity of website or app users, information is collected through tracking technologies placed on the website or app, which is then sent to that vendor to perform data analytics. If the collected information includes PHI, it is protected by HIPAA, and the HIPAA Privacy, Security, and Breach Notification Rules (“HIPAA Rules”) apply.[5] The rule for what qualifies as PHI in this context is much broader than one might think. Sometimes it is apparent: a patient portal that a patient must log in to almost certainly has access to PHI, such as the person’s medical or billing information. However, even an unauthenticated webpage that does not require a login, such as a health care provider’s public website, may provide a tracking technology vendor access to PHI. For example, tracking technologies might collect identifying information, such as an individual’s email address or IP address. If that person then begins searching for a provider or information on a particular medical condition, which is also tracked and sent to the vendor, the regulated entity is now disclosing PHI to the vendor.[6] Likewise, mobile apps may collect information such as health and billing information, as well as information about the user’s device (fingerprints, network location, etc.). This, too, is PHI, and any disclosure to the vendor must comply with HIPAA. Purported Class Action Lawsuits In recent months, several health plans and hospital systems have been the target of purported class action lawsuits from private plaintiffs alleging that the defendants utilized tracking technology vendors and unlawfully disclosed PHI without individual consent. Because there is no private right of action under the HIPAA Rules, these lawsuits do not bring HIPAA claims. But they appear to use alleged HIPAA Rule violations as a basis for claims under the Electronic Communication Privacy Act of 1986, the Computer Fraud and Abuse Act, and state law common law privacy claims. Accordingly, this is not merely a technical HIPAA matter, and can result in real consequences. What Should Regulated Entities Do to Comply with HIPAA When Using Tracking Technology Vendors? Make sure a Business Associate Agreement (“BAA”) is in place. A tracking technology vendor is a Business Associate when it creates, receives, maintains, or transmits PHI on behalf of a Covered Entity.[7] Further, disclosures to the vendor must be permitted by the HIPAA privacy rule, and only the minimum necessary PHI for the applicable purpose may be disclosed. If a BAA is not practicable or sufficient (e.g., there is no applicable permitted disclosure under the HIPAA privacy rule), the regulated entity must obtain individuals’ HIPAA-compliant authorization before any disclosure to the vendor occurs.[8] It is worth noting here certain mechanisms that do not qualify as HIPAA-compliant authorization: Privacy policy or terms of use. While a regulated entity may disclose the use of tracking technology here, that is insufficient to permit a disclosure of PHI that requires an individual’s authorization under the HIPAA privacy rule. Website banners asking individuals to accept or reject tracking technologies, such as cookies. A tracking technology vendor that promises to de-identify PHI before using information it receives or promises not to save PHI, because disclosure has already occurred at that point. Apply administrative, physical and technical safeguards to electronic PHI, as required under the Security Rule (e.g., encrypt PHI sent to the vendor), and consider and address tracking technologies when performing risk assessments. Notify individuals, the Secretary, and the media as required if a breach occurs. Final Thoughts HIPAA-regulated entities that utilize tracking technologies, and in particular, tracking technology vendors, must remain vigilant as to how PHI may be collected on various platforms. In particular, be aware that even a public, unauthenticated webpage could result in disclosure of PHI due to identity- or device-tracking pixels. When using a tracking technology vendor, a BAA must be in place, and the purpose of the disclosure must be permitted under the HIPAA Rules. Failure to do could result in impermissible disclosure of PHI, constituting a violation of the HIPAA Rules. The practice could also attract claims from private plaintiffs under various statutory and common law theories. Be proactive in addressing this potential gap in your privacy program; do not wait until the problem finds you. [1] 45 CFR § 160.103. [2] Use of Online Tracking Technologies by HIPAA Covered Entities and Business Associates, Dep’t of Health & Human Services (Dec. 1, 2022), https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/hipaa-online-tracking/index.html - ftn8. [3] Id. [4] See https://www.facebook.com/gpa/blog/the-facebook-pixel. [5] See 45 CFR parts 160 and 164. [6] https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/hipaa-online-tracking/index.html - ftn8. [7] Id. [8] 45 CFR § 164.508(b).
March 15, 2023
Recent DOJ Settlements Involving DME Manufacturers Highlight Important Anti-Kickback Considerations
The Department of Justice (“DOJ”) recently announced two settlement agreements, both involving durable medical equipment (“DME”) companies, following allegations that the companies had violated the Anti-Kickback Statute (“AKS”). The AKS, found at 42 U.S.C. § 1320a-7b, prohibits the exchange of anything of value (i.e., remuneration) with any intent to induce referrals for services or products reimbursable by federal health care programs. These settlements highlight two important reminders when it comes to complying with the AKS: (1) illegal remuneration can come in many forms and need not be monetary; and (2) commission-based compensation, while allowed for employees, is improper remuneration with regard to independent contractors. The first settlement involved a DME manufacturer that allegedly misled federal health care programs, including Medicare, Medicaid, and TRICARE, by paying kickbacks to DME suppliers. Specifically, the manufacturers provided DME suppliers with data about physician prescribing practices to aid their marketing efforts. In exchange, those suppliers then marketed the manufacturer’s products to providers. This resulted in DME suppliers submitting false claims for respiratory-related equipment following Respironics’ illegal inducements. Under the settlement terms, Respironics agreed to pay over $24 million in total to the United States and various affected states. Respironics also entered into a five-year corporate integrity agreement (“CIA”) with the U.S. Department of Health & Human Services Office of Inspector General (“HHS-OIG”). This settlement agreement makes clear that anything of value – even data – can be considered illegal remuneration under the AKS. Even if there is no marginal cost involved from the perspective of the data provider, data nonetheless can have value to the recipient. Consequently, product manufacturers, health care providers and others should recognize that value in any form can be the basis for anti-kickback allegations. The second settlement involved a DME manufacturer that produces knee braces and related products. It was alleged that the supplier paid an independent sales representative and the representative’s company commission payments ranging from 20-35% of VQ’s net revenue on every knee brace ordered by a particular set of providers. The providers then submitted claims for the braces allegedly contaminated by these kickbacks. The sales representative was able to “establish itself as the exclusive brace supplier” for several providers and collect millions of dollars in annual brace sales, according to the DOJ press release. Notably, this settlement was the result of an independently-prompted government investigation of Medicare claims data. Under the settlement terms, the DME manufacturer agreed to pay $2.25 million and entered into a five-year CIA with HHS-OIG. The issue of commission payments was also addressed early last year in United States v. Mallory, 988 F.3d 730 (4th Cir. 2021), wherein a federal court ordered a blood testing laboratory and its contracted sales agents to pay more than $100 million in damages after finding that the lab’s commission-based compensation to its contractors violated the AKS. These recent events illustrate that commission-based compensation arrangements with independent contractors are still an issue whenever federal health care programs are involved. And while there is an AKS safe harbor for commission payments to employees (42 C.F.R. § 1001.952(i)), the Department of Health and Human Services has made clear that commission payments for contracted services are not likewise protected. The DOJ has established its intent to aggressively scrutinize and prosecute such arrangements. In summary, these DME manufacturer settlements underscore two important AKS guidelines for all health care service and equipment providers: (1) be aware of untraditional items of value, such as data, that could be considered illegal remuneration; and (2) avoid commission-based compensation arrangements with independent contractors whenever federal program provide reimbursement for the products or services.
October 19, 2022

