◂ All Posts

AI and Data Analytics Are Rewriting Healthcare Compliance Risk

As a healthcare attorney and full-time compliance officer with more than 15 years in this field, I've watched the compliance landscape shift in ways that would have been genuinely hard to predict even five years ago. The shift I'm seeing right now is the one that keeps me up at night, not because it's frightening, but because most providers I work with are not fully prepared for it. Artificial intelligence and advanced claim data analytics have moved from back-office insurance company tools into the center of every fraud investigation and audit I'm handling. That changes everything about how risk is assessed, flagged, and prosecuted.

When I think back to cases I worked on during operations like "Operation Brace Yourself" and "Operation Double Helix," the government's ability to process claim data was significant, but it had real limits. Investigators were largely pulling billing records, running comparisons against peer benchmarks, and looking for outliers the old-fashioned way. Time-consuming. Pattern recognition that required human analysts working through mountains of data. That model still exists, but it's no longer the ceiling. It's now the floor.

What I'm seeing now, both in my litigation work and in my role overseeing compliance for a major multi-specialty group in Miami, is that payers and government agencies are running predictive models across claims data before a provider ever receives a letter. They're identifying billing patterns, comparing documentation to submitted codes at scale, and flagging anomalies in ways that are faster and far more precise than anything that existed when I started practicing. The upside of that capability is catching genuine fraud earlier. The very real downside is that a provider with an honest documentation problem, not a fraudulent one, can end up in the same initial flag pool as a provider who is deliberately overbilling.

That distinction matters enormously. One of the biggest misconceptions I run into is that a provider thinks they can simply return overpayments and move on. In my experience, that's not how these investigations resolve once the data has triggered a formal review. What starts as a billing irregularity identified by an algorithm can escalate into a criminal matter. The providers who fare the best are the ones who already have a compliance program that generates its own internal data, creating a defensible record that shows good faith, self-correction, and a systematic approach to billing accuracy before anyone came knocking.

This is the part of the shift I find most consequential: compliance programs are no longer just about having a policy manual and a training log. They need to generate and preserve data. If the government is using analytics to build a case, the defense needs analytics to counter it. In my compliance work, I've started building internal audit functions that mirror, to a reasonable degree, the kind of claim pattern analysis that payers are using on the other side. Not to find problems and bury them, but to find them first, correct them, and document that correction thoroughly.

Electronic health records have added another layer of complexity to this picture. On one hand, EHR systems create a detailed, timestamped record of clinical decision-making that didn't exist with paper charts. On the other hand, template-driven documentation, copy-forward notes, and auto-populated fields have given investigators new avenues to argue that records don't reflect genuine clinical encounters. I've seen cases where a provider's documentation looked perfect on the surface but fell apart under scrutiny because every note had identical language across dozens of patients. That's a problem an algorithm can spot in minutes.

The providers who will be in the strongest position over the next several years are the ones who treat their EHR as a legal document from day one, not an afterthought. That means training clinicians to document the actual clinical picture, not just click through a template. It means conducting regular internal audits that are specific to your specialty's billing patterns. And it means having legal and compliance counsel who understands both the regulatory environment and the data landscape well enough to spot what the government is likely to see before the government sees it. If you'd like to understand more about how I approach these issues for healthcare providers and medical practices, the about page covers my background in more detail.

Where I see this heading is toward a model where compliance is essentially a continuous data function, not an annual review. The practices that build that infrastructure now, before they receive a subpoena or a post-payment audit demand, are the ones that will have the most defensible position and the most options. That's the standard I hold my own compliance work to, and it's the conversation I'm having with every client I work with right now. To connect on how any of this applies to your practice or organization, feel free to reach out through the contact page.