Wisconsin Noncompete Bill Would Restrict Noncompetes for Medical Practitioners

Client Alert | November 2025

Wisconsin Noncompete Bill | Wisconsin Senate Bill 657 would materially change how health care organizations use noncompetes with certain practitioners. Although the bill did not pass in the 2025-2026 session, it signals continued scrutiny of physician and provider mobility and may inform future proposals.

Key Takeaways

  • The Wisconsin Noncompete Bill, Senate Bill 657 did not become Wisconsin law in the 2025-2026 session and, given its history to date, does not appear likely to pass this session.
  • If reintroduced and enacted, the proposal would create a statutory 24-month limit for covered medical-practitioner noncompetes.
  • The most significant operational change from the Wisconsin Noncompete Bill would be the loss of enforcement after an employer-initiated termination, a scenario where current law may still allow a physician noncompete to be enforced.
  • Health care employers and providers should treat the bill as a signal to reassess restrictive-covenant strategy, monitor future legislative activity and consult their state representatives for current information.

Bottom Line: The Wisconsin Noncompete Bill did not pass and has no immediate legal effect, but it reflects continued interest in limiting health care noncompetes. Providers and medical practices should monitor future developments and use the proposal as a prompt to review whether their current restrictive-covenant strategy remains practical, enforceable and aligned with business needs.


Background

Current Wisconsin law evaluates noncompetes through a fact-specific reasonableness framework. Courts have suggested that an 18-month restriction may be the practical outer boundary in some circumstances, but enforceability still depends on the agreement and business context. Importantly, current law may still allow enforcement of an otherwise valid noncompete even when the employer initiates the termination, which can remove an employed physician from the local market where the physician had been practicing. Senate Bill 657 would have moved beyond that framework by adding practitioner-specific statutory limits.

Strategic Significance of the Wisconsin Noncompete Bill Proposal

Twenty-four-month limit

For covered practitioners, a noncompete generally would be unenforceable if it restricts practice for more than 24 consecutive months after the practitioner’s first day of employment with the employer.

A restriction exceeding that limit would be void in its entirety, including provisions that might otherwise be viewed as reasonable.

The practical effect would be a clearer statutory ceiling for covered practitioner noncompetes, reducing reliance on a case-by-case assessment of duration.

The employer-initiated termination provision is the bill’s most significant practical change. The proposal would make a covered noncompete unenforceable if the employer terminates the practitioner’s employment for any reason.

That would materially alter the current risk calculus. Under current law, employer-initiated termination does not automatically defeat an otherwise enforceable noncompete. As a result, a physician whose employment is ended by the employer may still be required to exit the local market or practice elsewhere, even though the physician did not choose the separation. The proposal would have changed that result for covered practitioners.

In short, the employer-initiated termination provision would shift leverage in a key separation scenario. A practice that ends a physician’s employment could no longer rely on the noncompete to keep that physician out of the local market, increasing the need to plan separations carefully and to rely on narrower protections tied to confidential information, patient relationships and orderly transitions.

Covered Practitioners

The bill would apply to noncompetes involving the following categories of practitioners:

  • Advanced practice registered nurses;
  • Advanced practice nurse prescribers;
  • Physicians;
  • Physician assistants; and
  • Psychologists.

Because coverage would depend on the bill’s definitions, employers would need to confirm which roles fall within any final statutory language before revising agreements or enforcement strategy.

Effective Date and Initial Applicability

The proposed limits would apply to covered noncompetes entered into, extended, modified or renewed on or after the applicable effective date.

Most provisions would take effect the day after publication, while certain definition changes may take effect later depending on related legislation.

Legislative status of the Wisconsin Noncompete Bill

The bill advanced beyond introduction, including a public hearing and a favorable Senate Health Committee recommendation by a 4-1 vote on February 10, 2026.

It ultimately failed to pass on March 23, 2026. Given that history, the proposal does not appear likely to pass this session and has no immediate legal effect. Providers and health care employers may wish to monitor future legislative activity and talk with their state representatives for the most current information. The committee activity nevertheless suggests that limits on health care noncompetes may remain a live policy issue in future sessions.

Monitoring Legislative Updates

Because the bill did not pass but may signal future legislative interest, providers and medical practices should consider using alert tools rather than relying on periodic manual checks. The Wisconsin Legislature’s Notification Service allows users to receive email updates tied to specific proposals, subjects, committees, legislative authors and administrative rules. Relevant alerts may include terms such as “noncompete,” “medical practitioner,” “physician,” “health care,” and any future proposal number if similar legislation is reintroduced.

  • Subscribe to proposal-specific alerts if a similar bill is introduced;
  • Set subject or keyword alerts for health care noncompete developments;
  • Follow relevant committee activity, including hearings, amendments and executive sessions;
  • Designate an internal owner to review alerts and escalate material developments; and
  • Periodically confirm current status with counsel or state representatives when legislative activity resumes.

Wisconsin Noncompete Bill | Practical Impact for Physicians and Medical Practices

For physicians and other covered practitioners, a similar proposal would provide greater certainty and improve mobility after an employer-initiated separation. Most importantly, it would reduce the risk that a physician is forced out of the local market and becomes unavailable to patients and referral networks after the employer ends the relationship.

For medical practices, health systems and other health care employers, this provision would require closer planning around separation decisions. Noncompetes would become less reliable as a retention and post-employment protection tool when the employer initiates termination, and the risk-management focus would shift toward narrower protections, stronger agreement-management practices and careful consideration of local market impact.

Employer Risks

For employers, the primary risk is strategic uncertainty. Current law may still permit enforcement after an employer-initiated termination, but similar future legislation could narrow that option and change the leverage employers have in physician separations. Health care organizations that rely heavily on noncompetes should be prepared for increased enforcement uncertainty, local market-access concerns, and greater scrutiny of whether broad restrictions remain necessary.

Operationally, the risk is that agreements, templates and separation practices may not keep pace with legislative or market expectations. Employers should assume that physician noncompetes—especially those triggered after employer-initiated termination—will continue to draw attention and should plan for alternatives that protect legitimate business interests without unnecessarily limiting patient access or provider availability.

Risk Mitigation Plan

Health care employers can reduce uncertainty by treating restrictive-covenant management as an ongoing governance issue rather than a one-time contract exercise. A practical mitigation plan should focus on the following priorities:

  • Map current exposure. Inventory physician and provider agreements, identify which roles have noncompetes, and flag restrictions tied to employer-initiated termination.
  • Prioritize high-risk agreements. Review covenants with longer durations, broad geographic scope, unclear triggering events, or application to hard-to-replace providers in local markets.
  • Strengthen separation planning. Build a process for evaluating noncompete strategy before employer-initiated termination decisions are finalized, including patient-access, referral-network and operational continuity considerations.
  • Shift protection to narrower tools. Update agreements to emphasize confidentiality, trade-secret, nonsolicitation, repayment, transition and patient-information provisions where they better match the business risk.
  • Centralize oversight. Assign responsibility for maintaining templates, tracking renewals and amendments, monitoring legislative alerts, and coordinating with counsel when enforcement or policy changes are under consideration.

Concise Employer Action Plan

  1. Inventory existing agreements. Identify all physician and provider contracts with noncompetes, especially those tied to employer-initiated termination.
  2. Assess enforcement and market risk. Prioritize restrictions that could limit physician availability in key local markets or create patient-access concerns.
  3. Update separation planning. Review noncompete implications before employer-initiated terminations and build transition plans for patients, referrals and operations.
  4. Strengthen alternative protections. Use confidentiality, trade-secret, nonsolicitation, repayment, transition and patient-information provisions where they better match the risk.
  5. Monitor legislative activity. Assign an internal owner to track alerts, consult counsel and escalate developments if similar legislation is reintroduced.

Executive Considerations

Health care leaders should use the proposal as a prompt to evaluate whether their current restrictive-covenant program is aligned with business needs, workforce strategy and potential legislative change. Key questions include:

Employer Action Checklist

  • Inventory all physician and provider agreements that include post-employment noncompetes.
  • Identify which covered roles could be affected by any future medical-practitioner noncompete legislation.
  • Review noncompete durations, geographic scope and triggering events for enforceability and business necessity.
  • Evaluate how employer-initiated termination affects current enforcement strategy and local market access.
  • Centralize tracking of templates, renewals, amendments and new agreements.
  • Strengthen narrower protections, including confidentiality, trade-secret, nonsolicitation, repayment, transition and patient-information provisions.
  • Assign responsibility for monitoring legislative alerts and escalating material developments.
  • Consult counsel before changing forms, enforcing existing agreements or responding to renewed legislative activity.
  • Which agreements contain noncompetes and which roles they cover;
  • Whether current restrictions remain commercially necessary and defensible;
  • How separation scenarios affect enforcement risk;
  • Whether templates, renewals and amendments are centrally tracked; and
  • Whether alternative protections can address the same risks with less enforcement uncertainty.

In practical terms, organizations should consider whether confidentiality, trade-secret, nonsolicitation, repayment, transition and patient-information provisions provide more targeted protection than broad post-employment noncompetes. Any changes should be evaluated under current Wisconsin law and, if a similar bill is introduced, against the final statutory language and effective dates.

This client alert is for general informational purposes only and does not constitute legal advice. Legislative proposals may change, and the status described above is limited to the materials provided.

Meta title:

Meta description: A proposed Wisconsin bill would restrict the use of noncompete agreements for medical practitioners. Learn what the legislation could mean.

Meta keywords:

Open Graph title: Wisconsin Bill Would Restrict Noncompetes for Medical Practitioners

Open Graph description: Proposed Wisconsin legislation could limit noncompete agreements affecting medical practitioners and healthcare employment.

URL slug: wisconsin-noncompete-bill-medical-practitioners

Posted in Wisconsin Health Laws | Comments Off on Wisconsin Noncompete Bill Would Restrict Noncompetes for Medical Practitioners

The Physician Board Member – Meeting Your Responsibilities as a Director

Understanding Legal, Ethical, and Practical Obligations for Healthcare Leaders

Physician Director Duties Image

Serving as a board member gives physicians a meaningful opportunity to shape the strategic direction of healthcare organizations and support their long-term success. The role also carries legal and ethical obligations that directors must understand, document, and fulfill to protect the organization, its patients, and themselves.

This overview is designed to help physician directors understand their core fiduciary obligations, recognize common governance risks in healthcare settings, and identify practical steps for participating effectively in board decision-making.

The Legal Duties of Board Members

Physician board members are subject to the same legal standards as other directors. These standards generally include three fiduciary duties: care, loyalty, and obedience. The duty of care requires directors to prepare for meetings, review relevant materials, ask informed questions, and act with the diligence that a reasonably prudent person would exercise in similar circumstances. The duty of loyalty requires directors to put the organization’s interests ahead of personal, professional, or financial interests, including by disclosing potential conflicts. The duty of obedience requires directors to help ensure that the organization follows applicable laws, regulations, and governing documents.

Because fiduciary obligations and liability protections vary by state, organization type, and governing documents, physician directors should treat this overview as a governance guide rather than legal advice and consult qualified counsel when specific legal questions arise.

Practical Responsibilities and Best Practices

In addition to legal duties, physician directors must actively participate in board meetings, contribute their clinical expertise, and support the board in making sound decisions. This involves understanding the organization’s mission, financial health, and strategic goals. Directors should ask thoughtful questions, challenge assumptions when necessary, and advocate for patient safety and quality of care. Staying informed about regulatory changes affecting healthcare is also crucial, as is participating in ongoing education and training for board members.

Before each board meeting, physician directors should review the agenda, financial and quality reports, compliance updates, and any materials involving clinical operations or patient safety. They should note questions in advance, identify potential conflicts of interest, and be prepared to explain how proposed decisions may affect patients, clinicians, and organizational risk.

Ethical Considerations for Physician Directors

Physicians bring a unique perspective to the boardroom, often serving as a bridge between clinical operations and organizational leadership. Ethical considerations include maintaining patient confidentiality, promoting equitable access to care, and ensuring that board decisions align with the organization’s values and ethical standards. Physician directors should be mindful of situations where their medical judgment may influence board decisions and strive to balance their clinical responsibilities with their fiduciary obligations.

Managing Conflicts of Interest

Healthcare organizations often face complex conflicts of interest, particularly when board members are also practicing physicians. Directors must disclose any relationships, financial interests, or affiliations that could impact their impartiality. Boards should have clear policies for managing conflicts, including recusal from discussions or votes where a director’s interests may be compromised.

Conflict of Interest Policies

A strong conflict-of-interest policy helps the board identify, evaluate, document, and manage situations where a director’s personal, professional, financial, or clinical interests could affect independent judgment. For physician directors, relevant conflicts may include employment relationships, ownership or investment interests, referral arrangements, consulting agreements, medical staff leadership roles, relationships with vendors, participation in competing organizations, or family relationships involving the organization.

Effective policies should require annual written disclosures, prompt updates when new conflicts arise, review by a designated board committee or governance leader, clear criteria for determining whether a conflict exists, and written documentation of how the conflict was handled. When appropriate, the policy should require the conflicted director to leave the discussion, abstain from voting, and avoid receiving confidential information related to the matter unless the board determines that limited participation is necessary and properly documented.

Boards should also distinguish between actual conflicts, potential conflicts, and perceived conflicts. Even when a physician director believes they can remain objective, the appearance of divided loyalty can undermine trust in board decisions. A consistent disclosure and recusal process protects both the organization and the director by showing that decisions were made transparently, independently, and in the organization’s best interests.

Risk Management and Liability

Board members may face personal liability for breaches of duty or failure to comply with regulations. Physician directors should ensure the organization maintains appropriate insurance coverage, such as Directors and Officers (D&O) liability insurance, and understand the limits and protections these policies provide. Regular review of compliance protocols and risk management strategies is essential to safeguard both the organization and its directors.

Park Doctrine and Responsible Corporate Officer Risk

The Park doctrine, also known as the responsible corporate officer doctrine, comes from United States v. Park and recognizes that corporate leaders with authority to prevent or correct regulatory violations may face personal liability when they fail to use that authority. In healthcare settings, this principle underscores that physician directors should not treat compliance, quality, safety, or public-health risks as purely operational matters delegated to management. Directors should ensure that reliable reporting systems exist, respond to red flags, document board oversight, and confirm that corrective actions are followed through when compliance concerns arise.

Examples of Park doctrine risk include a senior leader failing to correct repeated sanitation or contamination problems after regulatory warnings; executives at an FDA-regulated organization allowing misbranded or adulterated drugs, devices, or food products to remain in distribution; or healthcare leaders ignoring recurring compliance reports about unsafe clinical practices, deficient corrective action, or public-health risks. For physician directors, these examples show why board minutes, compliance dashboards, audit follow-up, and documented escalation of unresolved concerns are important evidence of active oversight.

Additional Liability Case Examples

Several liability examples illustrate the types of facts that can create governance risk for healthcare directors. In In re Caremark International Inc. Derivative Litigation, the court emphasized that boards must make a good-faith effort to ensure that reasonable information and reporting systems exist for legal compliance. Later oversight cases, including Marchand v. Barnhill, reinforced that boards overseeing mission-critical risks must receive and monitor reliable compliance information rather than remain passive.

Nonprofit healthcare cases also show how board inattention can lead to personal exposure. In the Lemington Home for the Aged litigation, former directors and officers faced liability allegations tied to poor financial oversight, incomplete or missing minutes, weak board attendance, and failure to respond to management problems. In litigation involving Cheboygan Memorial Hospital, claims were allowed to proceed against certain directors based on alleged conflicts of interest, financial-control concerns, billing and coding issues, and decisions made while the hospital was in financial distress.

FDA and public-health enforcement examples are also relevant for physician directors. Responsible corporate officer cases have involved executives at drug, device, and food companies where regulators alleged misbranding, adulteration, unlawful promotion, manufacturing failures, or failure to correct known compliance problems. These examples underscore that boards should insist on credible compliance reporting, clear escalation pathways, documented corrective action, and timely follow-up when patient safety or regulatory risks are identified.

Recommendations for Physicians Serving on Boards

  • Prepare consistently by reviewing board materials, financial reports, quality data, compliance updates, and clinical-risk information before each meeting.
  • Ask informed questions when reports are incomplete, risks are unclear, or proposed decisions may affect patient safety, quality of care, access, or regulatory compliance.
  • Disclose conflicts of interest early and fully, including financial relationships, referral arrangements, employment ties, leadership roles, or affiliations that could affect independent judgment.
  • Document oversight through clear board minutes, follow-up requests, committee reports, and evidence that identified concerns were reviewed and addressed.
  • Support reliable reporting systems for compliance, quality, safety, privacy, billing, and public-health risks, and escalate unresolved red flags when management responses are insufficient.
  • Maintain appropriate board education on fiduciary duties, healthcare regulation, risk management, D&O insurance, indemnification protections, and emerging compliance priorities.
  • Balance clinical expertise with fiduciary responsibility by contributing physician insight while keeping the organization’s mission, legal obligations, and patient-centered priorities at the forefront.

Physician Board Member Checklist

  • Review the organization’s mission, bylaws, committee charters, conflict-of-interest policy, and code of conduct.
  • Confirm expectations for board attendance, committee participation, confidentiality, and preparation.
  • Understand the organization’s financial condition, strategic priorities, quality metrics, compliance program, and major operational risks.
  • Review D&O insurance, indemnification provisions, and any limitations on director protections.
  • Disclose all potential conflicts, including employment relationships, ownership interests, referral arrangements, outside leadership roles, and family or professional ties.
  • Prepare for each meeting by reviewing materials in advance and identifying questions about quality, safety, compliance, finance, strategy, and patient impact.
  • Ask management to clarify unclear risks, incomplete data, unresolved audit findings, or repeated compliance issues.
  • Ensure that board minutes accurately reflect major discussions, questions raised, decisions made, conflicts disclosed, recusals, and follow-up requests.
  • Monitor whether corrective actions are completed after compliance, quality, safety, or public-health concerns are identified.
  • Participate in ongoing board education on fiduciary duties, healthcare regulation, risk oversight, ethics, privacy, billing compliance, and emerging governance issues.

Conclusion

Serving as a physician board member is a meaningful opportunity to shape healthcare delivery, strengthen organizational policy, and bring clinical judgment into strategic decision-making. It also requires disciplined attention to fiduciary duties, ethical obligations, conflict management, compliance oversight, and documented follow-through. Physician directors are most effective when they prepare carefully, ask informed questions, respond promptly to red flags, and keep the organization’s mission and patient-centered responsibilities at the forefront. By approaching board service with rigor, independence, and transparency, physicians can help their organizations navigate complex healthcare risks while protecting patients, supporting sound governance, and upholding the integrity of the medical profession.

Posted in Accountable Care Organizations, Ambulatory Surgery Centers, Governance, Medical Staff Organization & Structure, Physician Issues, Wisconsin Health Laws | Comments Off on The Physician Board Member – Meeting Your Responsibilities as a Director

Concierge Medicine Agreements – Five Key Contract Clauses for Medical Practices

Concierge Medicine Contracts

Summary: Concierge medicine agreements should clearly address membership benefits, refund and cancellation policies, Medicare-related disclosures, arbitration provisions, and fee-adjustment mechanisms to help medical practices manage legal risk and patient expectations.

Concierge medicine, direct primary care, and membership-based medical practices can offer physicians a more flexible practice model, closer patient relationships, and a more predictable revenue stream. At the same time, the written concierge medicine agreement supporting that model requires careful attention. Vague, inconsistent, or outdated contract terms can create avoidable legal risk for the practice and confusion for patients. Before launching a new concierge medical practice or renewing an existing membership program, practices should review the following five contract clauses carefully.

1. Define the Scope of Concierge Medicine Membership Benefits

The agreement should clearly describe what the patient receives in exchange for the membership fee. This is often where misunderstandings arise. If the scope of benefits is unclear, patients may assume the fee includes services the practice intended to bill separately or does not provide. A well-drafted scope provision should distinguish enhanced access, administrative support, wellness planning, or other membership benefits from separately billable clinical services.

Drafting consideration:

Clear scope language can help manage patient expectations, support consistent billing practices, and reduce the risk that the membership fee will be characterized as payment for covered medical services.

2. Address Refund and Cancellation Policies in the Concierge Medicine Agreements

Refund and cancellation provisions should be tailored to the practice’s membership model rather than treated as boilerplate. When a patient relationship ends, unclear terms can lead to disputes over timing, notice, unused membership periods, administrative fees, or non-refundable amounts. The agreement should provide a practical process that both the practice and the patient can follow.

Issues to address:

  • Require written notice for cancellations.
  • Define pro-rata refund calculations based on the portion of the membership period used.
  • Clearly state any administrative fees, non-refundable deposits, or other exclusions.

3. Include Medicare Disclosures for Concierge Medicine Patients

Practices that serve Medicare beneficiaries should pay particular attention to how the agreement describes membership fees and covered services. The agreement should not suggest that the membership fee replaces, bundles, or otherwise covers services that are separately reimbursable by Medicare. The language should also be consistent with the practice’s Medicare participation status, including any opt-out arrangements where applicable.

Drafting consideration:

Patients should be able to understand which services are included in the membership fee, which services may be billed separately, and how Medicare-covered services will be handled.

4. Use Arbitration and Dispute Resolution Clauses Carefully in Concierge Medicine Agreements

Dispute-resolution provisions can help establish a predictable process for addressing disagreements, but they should be drafted with care. The provision should identify whether mediation, arbitration, or another process applies and should be written in a way that is understandable to patients and enforceable under applicable law. Language that is overly broad, one-sided, or unclear may undermine the provision’s effectiveness.

Drafting consideration:

  • Arbitration can reduce litigation costs but may limit patient recourse.
  • Clearly explain the binding nature of arbitration.
  • Consider mediation as a preliminary step before arbitration.

5. Plan for Annual Concierge Medicine Fee Adjustments

Concierge practices may need to adjust membership fees over time as costs, staffing, access models, or service offerings change. A fee-adjustment clause can help preserve flexibility while giving patients advance notice and a clear opportunity to evaluate continued participation in the program.

Drafting consideration:

The agreement should state when fees may be reviewed, how much advance notice patients will receive, and whether patients may cancel before a fee change becomes effective.

________________________________________

What should be included in a concierge medicine agreement? A concierge medicine agreement should identify the membership benefits, explain what services are included or excluded, describe refund and cancellation rights, address Medicare-related issues when applicable, and provide a process for fee changes and dispute resolution.

Why are Medicare disclosures important in concierge medicine contracts? Medicare disclosures are important because patients should understand whether the membership fee is separate from Medicare-covered services and how the practice handles services that may be billed to Medicare or another payer.

How often should a concierge medical practice review its membership agreement? A concierge medical practice should review its membership agreement before launching a program, before renewing enrollment materials, when changing fees or services, and whenever Medicare participation or billing practices change.

Conclusion

For concierge medicine practices, the membership agreement is both an operational document and a legal risk-management tool. It should reflect the practice’s current service model, billing approach, Medicare posture, cancellation procedures, and process for future fee changes. Periodic review of concierge medicine contracts can help ensure that the agreement remains accurate, patient-friendly, and aligned with applicable legal requirements.

Medical practices that are launching, revising, or renewing a concierge membership program should consider reviewing these provisions with counsel before enrollment materials are distributed or renewal communications are sent.

________________________________________

Posted in Consierge & Cash-Based Practices, Health Care Contracting, Physician Contracting and Alignment, Physician Issues, Wisconsin Health Laws | Tagged , , | Comments Off on Concierge Medicine Agreements – Five Key Contract Clauses for Medical Practices

Telehealth Membership Platforms: A Provider Compliance Guide

Telehealth Membership Platforms – Operational and Legal Considerations for Healthcare Providers

Introduction

Telehealth Membership Platforms

Telehealth has become a routine part of healthcare delivery in the United States, giving patients more convenient access to clinicians through digital platforms. Telehealth membership platforms, which offer patients ongoing access to virtual care for a recurring fee, can help providers expand access, improve continuity of care, and support more predictable patient engagement.

For healthcare providers and Telehealth Membership Platforms provider organizations, however, these models require careful attention to licensure, privacy, consent, prescribing, advertising, reimbursement, and state-law requirements before launch and throughout operations.

Regulatory Framework

Telehealth membership platforms are subject to a complex web of federal and state requirements. At the federal level, HIPAA governs the privacy and security of protected health information, including telehealth visits, messages, billing information, and related records. CMS rules may be relevant when a provider bills Medicare or Medicaid for telehealth services, while the FTC may scrutinize advertising, consumer-facing claims, and certain health data practices.

State laws vary widely, and providers must follow the rules that apply where the patient is physically located at the time of the encounter. These rules may address licensure, scope of practice, standards of care, informed consent, prescribing, documentation, privacy, reimbursement, and corporate practice restrictions. Providers should treat compliance as an ongoing operational responsibility rather than a one-time legal review.

What’s Allowed

  • Licensed Care Delivery: Providers delivering telehealth services generally must be licensed or otherwise authorized in the state where the patient is located. Licensure compacts may streamline multi-state practice but do not eliminate the need to confirm state-specific authorization.
  • Patient Privacy and Security: Providers must use appropriate safeguards for telehealth communications, storage, access controls, and vendor relationships, including business associate agreements when required.
  • Membership Fees: Recurring membership models may be permissible if the fee structure is designed so it does not create insurance, prepaid health plan, discount medical plan, or consumer-protection concerns under applicable state law.
  • Informed Consent: Providers may deliver care through telehealth when they obtain and document any consent required by state law, payer rules, or organizational policy before or during the encounter.
  • Patient Communications and Marketing: Providers may describe and promote telehealth services, but clinical claims, pricing descriptions, subscription terms, and access promises should be accurate, clear, and consistent with professional and consumer-protection rules.

What Isn’t Allowed

  • Unlicensed Practice: Providers should not treat patients located in states where they lack the required license, compact privilege, registration, or other authorization.
  • Improper Fee Structures: Membership fees that promise broad or unlimited care for a flat amount, obscure what is included, or shift financial risk to the provider organization may trigger state insurance or prepaid-plan concerns.
  • Improper Prescribing: Providers should not prescribe medications through telehealth unless federal and state requirements are satisfied, especially for controlled substances or medications that require an in-person evaluation, specific documentation, or another recognized exception.
  • Privacy and Security Failures: Providers should not use consumer-grade tools, unsecured devices, informal messaging channels, or vendors without appropriate safeguards when those tools handle protected health information.
  • Incomplete Consent or Documentation: Providers should not begin or continue telehealth services without documenting patient consent, clinical decision-making, patient location, encounter details, and follow-up instructions when required.

How Providers Can Mitigate Key Risks

Providers can reduce telehealth membership risk by turning compliance into repeatable clinical and operational workflows rather than treating it as a one-time launch review. The following mitigation steps should be built into scheduling, intake, clinical documentation, prescribing, billing, privacy, marketing, and periodic audit processes.

  • Mitigate licensure and patient-location risk: Confirm the patient’s physical location at every encounter, match clinicians only with patients in states where they are licensed or otherwise authorized, maintain a licensure matrix by clinician and state, and review compact participation, temporary practice rules, and state telehealth registrations before expanding into new markets.
  • Mitigate HIPAA privacy and security risk: Use telehealth platforms and vendors with appropriate safeguards, execute business associate agreements when required, limit access to patient information by role, train staff on secure communications and device use, and periodically audit access logs, vendor practices, and incident-response procedures.
  • Mitigate membership-fee and insurance risk: Clearly define what the membership fee includes and excludes, avoid promises of unlimited care that could create insurance-like risk, separate membership fees from covered services when billing payers, and make cancellation, refund, and pricing terms clear to patients.
  • Mitigate informed-consent and documentation risk: Use a standardized telehealth consent process, document patient consent and location, capture clinical findings and follow-up instructions, add prompts in the electronic health record for required telehealth fields, and audit sample records for completeness.
  • Mitigate prescribing risk: Create telehealth prescribing protocols, flag controlled substances and higher-risk medications for additional review, confirm whether an in-person evaluation or other requirement applies, train clinicians on federal and state prescribing limits, and establish escalation rules for in-person care or referral.
  • Mitigate advertising and patient-communication risk: Review marketing claims before publication, avoid guarantees about access, outcomes, prescriptions, or treatment results, clearly explain membership terms and emergency-care limitations, align website, app, email, and sales scripts, and retain records of approved marketing language.
  • Mitigate operational compliance risk: Assign ownership across legal, clinical, compliance, billing, privacy, and technology teams; monitor regulatory changes; update workflows as rules evolve; conduct periodic audits; and train new staff before they provide or support telehealth services.

Best Practices for Providers

Providers operating or participating in telehealth membership platforms should build compliance into day-to-day workflows. Key steps include confirming patient location at each encounter, verifying clinician authorization before scheduling visits, using HIPAA-compliant technology and appropriate vendor agreements, obtaining and documenting required consent, maintaining clear prescribing protocols, training staff on privacy and escalation procedures, and reviewing subscription terms for insurance, billing, and consumer-protection risk. Providers should also monitor federal and state updates, audit documentation periodically, and coordinate with legal, compliance, clinical, billing, and technology teams as the platform grows.

Conclusion

Telehealth membership platforms can expand access to care and strengthen ongoing patient relationships, but their success depends on disciplined compliance and clinical governance. Providers should structure these models around patient safety, accurate communications, secure technology, clear documentation, lawful prescribing, and state-specific practice requirements. By treating compliance as part of routine care delivery, provider organizations can use membership-based telehealth models more safely and sustainably.



Posted in Telemedicine | Comments Off on Telehealth Membership Platforms: A Provider Compliance Guide

Medicare Opt-Out – A Make-or-Break Decision for Concierge Physicians

Medicare Opt-Out Opting out of medicare

For physicians moving into concierge, direct-pay, or cash-based practice models, opting out of Medicare is a consequential compliance decision—not merely an administrative formality. A properly executed Medicare opt-out changes how the physician may treat and bill Medicare beneficiaries, how private contracts must be handled, and how the practice manages ongoing regulatory risk.

Key Compliance Points with Medicare Opt-Out

  • Medicare Opt-out is provider-specific and does not automatically apply to the entire practice, group, clinic, or care team. Example: If one physician opts out but an NP in the same practice remains enrolled, the practice may need separate scheduling, documentation, and billing workflows for each provider.
  • MAC affidavit timing and submission requirements must be mapped carefully before relying on private-pay arrangements with Medicare beneficiaries. Example: A participating physician planning to opt out at the start of a calendar quarter should confirm the affidavit submission deadline before signing or relying on private contracts for covered services.
  • Each Medicare beneficiary should sign a compliant private contract before covered services are furnished outside Medicare billing rules. Example: Before a Medicare beneficiary receives a concierge annual wellness-style visit from an opted-out physician, the signed contract should clearly explain that Medicare will not pay for the contracted services.
  • The practice should track each provider’s two-year Medicare opt-out cycle, renewal period, cancellation window, and MAC submission confirmation. Example: A compliance calendar can flag renewal and cancellation dates 90, 60, and 30 days in advance so the practice does not miss a critical deadline.
  • Separate workflows may be needed for opted-out providers and providers who continue to bill Medicare. Example: Intake staff may need a checklist showing whether the patient is seeing an opted-out physician, an enrolled NP, or another provider whose services remain billable to Medicare.
  • Opting out of Medicare does not eliminate obligations under AKS, Stark, state law, payer contracts, referral rules, or documentation standards. Example: A medical director agreement, referral arrangement, lease, or marketing relationship should still be reviewed for fair market value, commercial reasonableness, and referral-risk issues.
  • Audit-ready records should include affidavits, private contracts, beneficiary notices, billing decisions, renewal records, and compliance ownership assignments. Example: The practice should be able to quickly produce the signed private contract, affidavit confirmation, and billing rationale for a disputed Medicare beneficiary encounter.
  • Standardized contract language helps avoid inconsistent beneficiary obligations and reduces avoidable compliance risk. Example: If staff modify payment language for one patient but not another, the practice may create ambiguity about patient responsibility and undermine consistent enforcement.

1. File the MAC Medicare Opt-Out Affidavit Before Relying on Private Contracts

A physician or eligible practitioner must submit an opt-out affidavit to each applicable Medicare Administrative Contractor (MAC). The affidavit establishes the opt-out status and should be coordinated carefully with the timing of private contracts and the physician’s Medicare participation status.

  • For nonparticipating physicians, the initial two-year opt-out period generally begins when the affidavit is signed if it is filed within the required timeframe after the first private contract is signed.
  • For participating physicians, opt-out generally may begin only at the start of a calendar quarter, and the affidavit must be submitted in advance of that quarter.
  • The opt-out period runs for two years and may automatically renew unless the physician properly cancels the opt-out within the applicable timeframe.

Common compliance failures include filing with the wrong MAC, missing timing requirements, using incomplete affidavits, failing to track renewal or cancellation windows, and treating opt-out as practice-wide rather than provider-specific.

2. Sequence Private Contracts With Medicare Opt-Out Carefully

Private contracts are the operational backbone of a Medicare opt-out strategy. Each Medicare beneficiary must sign a compliant private contract before the physician furnishes non-emergency Medicare-covered services outside Medicare billing rules. If the affidavit and contract sequence is mishandled, services may remain subject to ordinary Medicare requirements until the opt-out is properly effective.

  • Use a separate private contract for each Medicare beneficiary.
  • Retain signed contracts for the full opt-out period and be prepared to produce them if requested.
  • Confirm that the contract states the beneficiary accepts full payment responsibility and understands that Medicare will not pay for services covered by the private contract.

The safest approach is to map the affidavit date, opt-out effective date, first private contract date, and first service date before collecting private-pay fees from Medicare beneficiaries.

3. Address Mid-Level Provider Implications

Medicare opt-out is provider-specific. In a concierge practice that uses nurse practitioners (NPs), physician assistants (PAs), or other eligible practitioners, the practice must determine which individual providers may opt out, which remain enrolled, and how each provider’s services will be billed or privately contracted.

  • Do not assume that a physician’s opt-out automatically covers the entire group, clinic, or care team.
  • Separate workflows may be needed for opted-out providers and providers who continue to bill Medicare.
  • Practices should review supervision, incident-to billing, reassignment, and documentation procedures before launching the concierge model.

4. Preserve AKS, Stark, and Other Compliance Controls

Opting out of Medicare does not remove the practice from broader healthcare fraud-and-abuse rules. The Anti-Kickback Statute (AKS), Stark Law, state fee-splitting rules, corporate practice restrictions, and payer-contract obligations may still affect the practice’s financial relationships and referral arrangements.

  • Review compensation, referral, and marketing arrangements for remuneration risk.
  • Confirm that ownership, lease, management, and professional-services arrangements are commercially reasonable and properly documented.
  • Maintain audit-ready records for opt-out affidavits, private contracts, beneficiary notices, billing decisions, and renewal tracking.

A Medicare opt-out strategy should therefore be integrated into the practice’s broader compliance program rather than handled as a one-time enrollment decision.

Medicare Opt-Out Compliance Tip

Create a centralized Medicare opt-out tracker that includes each provider’s affidavit date, effective date, MAC submission confirmation, private contract version, renewal cycle, cancellation deadline, and assigned compliance owner. Use standardized contract language and avoid ad hoc edits that could create inconsistent beneficiary obligations.

When handled correctly, Medicare opt-out can support a concierge practice model while preserving patient transparency and regulatory discipline. When handled casually, it can create billing exposure, contract disputes, repayment risk, and avoidable scrutiny. The decision should be planned, documented, and revisited before every renewal cycle.


Posted in Consierge & Cash-Based Practices, Medicare and Medicaid, Medicare and Medicaid Reimbursement, Physician Issues, Reimbursement & Payment Practices | Tagged , , , | Comments Off on Medicare Opt-Out – A Make-or-Break Decision for Concierge Physicians

Hybrid Concierge Models – Why Popularity Comes With Compliance Risk

Hybrid concierge models are gaining traction for a simple reason: they give physicians a way to offer a more personalized patient experience without walking away from traditional insurance. Patients can opt into a membership tier for enhanced access and non-covered amenities, while covered medical services continue to be billed through insurance. But that flexibility comes with a catch. If the membership program is not structured carefully, it can create questions about double billing, covered services, and even whether the practice is offering an unlicensed insurance product.

Hybrid Concierge Models Start With a Clear Line Between Membership Perks and Covered Care

The biggest compliance issue in a hybrid model is overlap. A membership fee should not pay for services that are already covered by insurance. If it does, the practice may face allegations that patients are being charged twice for the same care or that the membership tier is being used to move covered services outside the payer framework.

A stronger approach is to build the membership around clearly non-covered, non-clinical benefits, such as:

  • Enhanced access, such as same-day or extended-hours appointment availability, provided it does not replace or repackage standard covered visits.
  • Non-clinical amenities, such as wellness coaching, nutrition education, care navigation, appointment coordination, or personalized health planning.
  • Priority communication channels, such as direct phone or email access, provided they do not substitute for billable clinical encounters.

The key is clarity. Membership agreements, website copy, brochures, and staff scripts should all tell the same story: what the membership includes, what it does not include, and which services remain subject to insurance billing.

Be Careful With Popular Marketing Phrases for Hybrid Concierge Models

Phrases like “priority scheduling,” “longer visits,” and “direct physician access” can be compelling to patients, but they need guardrails. Without clear definitions, these terms may suggest that members are paying for preferential clinical care rather than non-covered conveniences or administrative access.

For example, a practice may define these benefits as follows:

  • Priority scheduling: expedited appointment availability within a defined timeframe, without guaranteeing a particular provider, diagnosis, treatment, or clinical outcome.
  • Longer visits: additional time dedicated to non-covered services, such as wellness planning, lifestyle discussions, or preventive education, clearly separated from billable medical evaluation and management services.

These distinctions should also show up in documentation. If a visit includes both billable clinical care and non-covered wellness or planning support, the record should make that separation clear.

Do Not Bundle Clinical Care Into the Hybrid Concierge Models Membership Fee

One of the most important rules for hybrid concierge programs is also one of the easiest to overlook: the membership fee should not include clinical services. Bundling medical care into the fee can raise serious issues under payer contracts, state insurance laws, and federal fraud-and-abuse rules.

Practices can reduce risk by building in a few practical safeguards:

  • Limit membership benefits to non-clinical services and administrative conveniences.
  • Bill clinical services through traditional insurance or patient-responsibility channels, as applicable.
  • Review membership agreements, payer contracts, patient communications, and marketing materials before launch and periodically thereafter.

Watch for Unlicensed Insurance Concerns

A hybrid model can also attract scrutiny if the membership fee looks like prepayment for future medical care. In that scenario, regulators may ask whether the practice is effectively selling an insurance product without a license.

  • Ensure the membership fee covers only non-covered services, administrative benefits, or amenities.
  • Avoid contract language suggesting that the fee provides medical coverage, prepaid care, or guaranteed clinical outcomes.
  • Conduct a benefit-mapping exercise that distinguishes covered services from non-covered membership benefits.

This is why benefit design, contract language, and marketing language should be reviewed together. A compliant agreement can still be undermined by promotional copy that overpromises what the membership provides.

The Takeaway

Hybrid concierge models can be an effective way to improve the patient experience and diversify practice revenue, but they require careful planning. Before launch, every proposed membership benefit should be mapped against covered services, payer obligations, and applicable legal requirements. The goal is simple: offer meaningful non-covered value to patients without turning the membership fee into payment for clinical care.

Posted in Consierge & Cash-Based Practices, Physician Contracting and Alignment, Physician Issues, Wisconsin Health Laws | Tagged , , , , | Comments Off on Hybrid Concierge Models – Why Popularity Comes With Compliance Risk

Cash-Based Clinics – A Regulatory Landscape More Complex Than It Appears

Cash-based medical practices often assume that avoiding insurance billing also avoids legal risk. In reality, the risk profile does not disappear—it shifts. Cash-Based Clinics that does not submit claims to Medicare, Medicaid, or commercial payors may still face meaningful exposure under state fee-splitting rules, corporate practice of medicine restrictions, consumer protection laws, telehealth requirements, and controlled-substance prescribing rules.


For owners, operators, management services organizations, and investors, the central lesson is straightforward: cash pay is not a compliance shortcut.

This article outlines the core regulatory issues cash-based clinics should evaluate before scaling, partnering with vendors, or entering into management arrangements.

1. Fee-Splitting and MSO Management Fee Risk

One of the most common risk areas for cash-based clinics is the relationship between a professional practice and a management services organization. MSOs are frequently used to provide administrative, staffing, marketing, technology, billing support, and other non-clinical services. In states with corporate practice of medicine restrictions, the MSO model can help separate clinical decision-making from business operations. However, the structure must be carefully designed.

The principal concern is fee-splitting. Many states prohibit physicians and other licensed professionals from sharing professional fees with unlicensed persons or entities. A management fee tied to a percentage of clinic revenue, professional collections, membership payments, or retainer revenue may be interpreted as an impermissible share of professional income. The issue is not limited to insurance-based practices; state-level fee-splitting and corporate practice rules may apply regardless of whether the patient pays cash.

Cash-based practices should therefore avoid assuming that a percentage-based management fee is safe simply because no insurance is involved. A more defensible structure typically uses a fixed or fair-market-value fee for defined services, supported by documentation showing what the MSO provides and why the fee is commercially reasonable.

2. Membership Fees and Insurance Characterization

Memberships, subscriptions, retainers, and concierge-style access models can be attractive to both clinics and patients. They may provide predictable revenue for the practice and a clearer service package for patients. But these arrangements can raise a threshold question: does the fee merely buy access to services, or does it function like insurance?

State insurance laws vary significantly, but regulators may scrutinize arrangements where a patient pays a recurring fee in exchange for a promise of future healthcare services, especially if the clinic assumes meaningful financial risk. The more a membership resembles prepayment for unlimited or uncertain future care, the more important it becomes to evaluate whether the arrangement could trigger insurance, risk-bearing, or consumer protection concerns.

Careful drafting matters. Membership terms should clearly describe what is included, what is excluded, how fees are charged, how patients may cancel, and whether any clinical services require separate payment. Clinics should also avoid marketing language that suggests comprehensive coverage, guaranteed treatment, or protection against future medical costs unless that language has been reviewed under applicable state law.

3. Telehealth Across State Lines

Telehealth in concierge medicine

Cash-based clinics should build telehealth compliance into operations rather than treating it as a technical add-on. Intake workflows should confirm patient location, provider eligibility, emergency protocols, informed consent requirements, and any state-specific restrictions. If the clinic advertises nationally, it should ensure that marketing reach does not exceed the states where clinicians may lawfully provide services.

Telehealth can help cash-based clinics expand their reach, but it also increases regulatory complexity. The key compliance question is usually where the patient is located at the time of the encounter. In many states, a clinician must be licensed or otherwise authorized in the patient’s state before providing care. This means that a clinic operating from one state may still need to comply with multiple states’ licensure, consent, recordkeeping, prescribing, and standard-of-care requirements.

Go to our Implementing Telehealth Patient Services

4. Controlled-Substance Prescribing and DEA Requirements

Controlled-substance prescribing presents a separate layer of risk, particularly for clinics that use telehealth. Practices should monitor federal requirements administered by the Drug Enforcement Administration, as well as state prescribing laws, professional board guidance, prescription drug monitoring program obligations, and documentation standards. The federal framework for telemedicine prescribing continues to evolve, including the anticipated Special Registration pathway for certain remote prescribing models.

Clinics should adopt written prescribing policies that address patient evaluation, identity verification, medical necessity, follow-up, refill protocols, and escalation procedures. These policies should be practical enough for clinicians to follow and specific enough to show that the clinic is not relying on a generic telehealth workflow for higher-risk prescribing.

Practical Compliance Steps

Cash-based clinics can reduce risk by addressing compliance before the model scales. Key steps include reviewing ownership and control structures under applicable corporate practice of medicine rules, documenting fair-market-value compensation for MSO services, evaluating membership terms under state insurance and consumer protection laws, maintaining a state-by-state telehealth matrix, and developing written prescribing policies for any controlled-substance services.

Practices should also revisit compliance whenever they add a new state, vendor, service line, investor, marketing channel, or payment model. Many regulatory problems emerge not when the clinic first opens, but when a simple local model becomes a multi-state or platform-based business.

Red Flag to Watch

A management fee tied to a percentage of revenue—especially membership or retainer revenue—should receive close legal review. Even where services are legitimate and commercially valuable, revenue-based compensation may create the appearance that a non-clinical entity is sharing in professional fees or influencing the economics of care.

Conclusion

Cash-based clinics can offer patients a simpler, more transparent healthcare experience. But the absence of insurance billing does not eliminate regulatory obligations. The most durable models are those that pair business flexibility with careful legal structure: clear separation between clinical and non-clinical functions, defensible compensation arrangements, transparent membership terms, state-specific telehealth controls, and disciplined prescribing protocols.

For practices, MSOs, and investors, the better question is not whether cash pay avoids regulation. It is whether the model has been structured to withstand the regulatory scrutiny that comes with growth.



Posted in Consierge & Cash-Based Practices, Fraud and Abuse, Medicare and Medicaid Reimbursement, Physician Issues, Wisconsin Health Laws | Comments Off on Cash-Based Clinics – A Regulatory Landscape More Complex Than It Appears

State Spotlight: Wisconsin, Illinois, and Michigan — Three Distinct Regulatory Environments

A regional comparison of physician practice requirements in the Midwest demonstrates that Wisconsin, Illinois, and Michigan present materially different regulatory considerations for concierge, membership-based, and cash-based medical practices. For physicians, practice administrators, and MSO partners, these differences affect how ownership structures are documented, how membership benefits are described, how telehealth services are delivered, and how compliance responsibilities are allocated across the practice model.

Across the three states, the principal compliance themes are ownership and control of the medical practice, characterization of membership fees, separation of clinical and administrative functions, telehealth licensure, and the distinction between covered medical services and non-covered membership benefits. Addressing these themes at the outset provides a more precise framework for evaluating the state-specific considerations that follow.

Wisconsin: CPOM Restrictions and Telehealth Flexibility

Wisconsin maintains Corporate Practice of Medicine (CPOM) restrictions that limit non-physician ownership and control of medical practices. These restrictions may present structural challenges for management services organizations (MSOs) and require careful contractual design to mitigate fee-splitting concerns. Physicians should ensure that management fees are fixed, commercially reasonable, and not calculated by reference to practice revenue.

Wisconsin’s telehealth framework has become more flexible, particularly in the period following the COVID-19 pandemic, thereby permitting broader use of remote-care modalities. Nevertheless, physicians should continue to evaluate licensure obligations, patient consent requirements, and documentation standards for each telehealth encounter.

Wisconsin practices using an MSO should document which services the MSO provides, how the fixed management fee was determined, and which decisions remain exclusively within the physician practice. The agreement should make clear that the MSO does not direct clinical judgment, control patient relationships, determine medical necessity, or receive compensation that varies based on professional revenue.

Recent enforcement activity has emphasized improper fee arrangements and unlicensed practice issues, reinforcing the importance of a documented compliance program. A Wisconsin-specific review should include the following measures:

  • Confirm that MSO agreements provide for fixed-fee compensation structures.
  • Verify that telehealth services satisfy applicable state licensure, consent, and documentation requirements.
  • Conduct periodic audits of billing and membership-fee practices to mitigate fee-splitting risk.

Illinois: Insurance-Code Sensitivity and MSO Enforcement

Illinois presents a heightened regulatory environment because membership fees may be subject to scrutiny if they appear to constitute prepayment for covered medical services. The state’s insurance-code framework may increase regulatory exposure when membership benefits are not clearly distinguished from insured or reimbursable care.

In Illinois, membership agreements should describe benefits in terms of access, administrative conveniences, care coordination, educational resources, or other non-covered services where appropriate. The agreement should avoid suggesting that the membership fee guarantees the delivery of medically necessary care, substitutes for insurance, or prepays for services that would otherwise be reimbursable by a payer.

MSO structures in Illinois warrant particular attention. Enforcement risk increases when contractual arrangements obscure the distinction between administrative management services and impermissible fee splitting. Physicians and practice owners should ensure that governing documents preserve clinical independence and clearly allocate administrative functions.

Practical risk-mitigation strategies for Illinois include the following:

  • Review membership agreements to avoid language suggesting insurance coverage or prepaid covered services.
  • Structure MSO fees as fixed, fair-market-value payments that are not tied to patient volume or practice revenue.
  • Maintain documentation evidencing the separation of clinical control from administrative support services.

Michigan: Hybrid Models and Strong CPOM Enforcement

Michigan has experienced increased interest in hybrid concierge models that combine traditional insurance billing with membership tiers for enhanced access or non-covered services. Although these models may be commercially attractive, they require precise benefit delineation to reduce regulatory and payer-contract risk.

Michigan also applies CPOM and fee-splitting principles with rigor, particularly where arrangements may implicate unlicensed practice concerns. Clear contractual provisions, transparent patient communications, and consistent operational controls are therefore essential.

For Michigan hybrid models, benefit mapping should identify each membership feature, determine whether the feature overlaps with an insured or reimbursable service, and specify how the practice will communicate that distinction to patients. This exercise should be reflected in patient-facing materials, internal workflows, and payer-contract reviews so that the model operates consistently in practice.

Key compliance practices for Michigan physicians include the following:

  • Map membership benefits to distinguish covered medical services from non-covered amenities or access-related benefits.
  • Review contracts and marketing materials for consistency with CPOM, fee-splitting, and payer requirements.
  • Monitor evolving state guidance, enforcement trends, and relevant case law.

Taken together, the three states illustrate different risk centers. Wisconsin places particular emphasis on ownership, control, and fixed-fee MSO structures; Illinois presents heightened sensitivity around whether membership fees resemble insurance or prepaid covered services; and Michigan requires particular care in hybrid models where membership benefits sit alongside traditional insurance billing. A practice operating across state lines should therefore avoid relying on a single standardized membership agreement without state-specific review.

Takeaway: Cross-Border Compliance Is Essential

Physicians practicing near state borders should structure concierge, membership-based, and cash-based models to comply with the laws of each jurisdiction in which they provide services to patients. A multi-state compliance framework should include the following elements:

For operational purposes, the compliance matrix should identify the applicable ownership restrictions, fee-structure limitations, telehealth requirements, patient-consent obligations, marketing-review standards, and payer-contract considerations for each state. It should also assign responsibility for periodic review so that updates to state law, enforcement priorities, or payer policies are incorporated into practice operations.

  • Maintain a jurisdiction-by-jurisdiction compliance matrix.
  • Adapt contracts, fee structures, telehealth workflows, and patient communications to applicable state requirements.
  • Engage counsel with experience in multi-state healthcare regulation and concierge-practice models.

By addressing these considerations proactively, practices can mitigate legal risk and support the development of sustainable, compliant membership-based models across the Midwest.

Posted in Wisconsin Health Laws | Comments Off on State Spotlight: Wisconsin, Illinois, and Michigan — Three Distinct Regulatory Environments

Understanding HIPAA and Its Interaction with State and Federal Confidentiality Laws

HIPAA privacy compliance, state health information confidentiality laws, Wisconsin medical record privacy, mental health record protections, and 42 CFR Part 2 substance use disorder records

Wisconsin Health Lawyer John Fisher

HIPAA Privacy Compliance as the Baseline Framework

Executive summary: HIPAA privacy compliance establishes a federal baseline for the protection, use, and disclosure of protected health information; however, HIPAA is not invariably the most restrictive or controlling legal authority for every medical record disclosure or patient privacy decision. Covered entities, business associates, health care providers, administrators, legal counsel, and compliance officers must evaluate each proposed disclosure under all applicable federal and state health information confidentiality laws, including state medical record confidentiality statutes, Wisconsin patient health care record privacy requirements, mental health record protections, HIPAA preemption rules, and 42 CFR Part 2 substance use disorder treatment record requirements. The appropriate compliance analysis should identify the record type, the purpose of the disclosure, the recipient, the applicable consent or authorization standard, any redisclosure restriction, and the legal standard that governs the particular disclosure at issue.

HIPAA Triage Process

This article explains how HIPAA privacy compliance interacts with state medical record confidentiality laws, Wisconsin health care record statutes, mental health record privacy protections, and 42 CFR Part 2 confidentiality rules for substance use disorder treatment records. It is intended to help health care providers, compliance officers, administrators, and legal counsel evaluate patient privacy disclosures, identify when HIPAA is only the baseline, and determine when a more specific federal or state privacy law may control the release of protected health information.

Summary: HIPAA, Part 2, and Health Information Confidentiality

This article addresses core health care privacy and compliance topics, including HIPAA privacy compliance, protected health information, state medical record confidentiality laws, Wisconsin health record privacy, mental health record confidentiality, 42 CFR Part 2 confidentiality rules, substance use disorder treatment records, SUD patient record confidentiality, HIPAA preemption, treatment-payment-health care operations disclosures, patient consent and authorization, redisclosure restrictions, and patient privacy disclosure workflows.

For compliance teams, the central issue is how HIPAA interacts with more protective state and federal confidentiality requirements. The analysis is especially important when patient information includes mental health records, substance use disorder records, Wisconsin patient health care records, or other specially protected health information that may require additional consent, documentation, breach-notification, redisclosure, or proceeding-use safeguards.

Why HIPAA Privacy Compliance Is Only the Starting Point

HIPAA, as a comprehensive federal regulatory framework governing the privacy and security of protected health information, has been effective in establishing broad institutional awareness within health care settings. Personnel generally understand that HIPAA prohibits unauthorized discussion of patient information outside the workplace and restricts disclosure of protected health information to third parties absent a valid regulatory basis, applicable exception, or patient authorization.

When a “HIPAA Issue” May Involve Other Privacy Laws

The prominence and institutional recognition of HIPAA are beneficial insofar as they reinforce regulatory awareness and promote the protection of patient confidentiality. From a legal and compliance perspective, however, such prominence may also create the mistaken assumption that any potential disclosure of patient information is solely a “HIPAA issue.” Although this assumption reflects an appropriate sensitivity to confidentiality concerns, it may obscure the applicability of other legal authorities that impose equal or greater restrictions in particular circumstances.

Medical Record Disclosure Compliance Under Federal and State Law

Accordingly, HIPAA should be understood as one component of a broader legal framework governing health information confidentiality and patient privacy compliance. While HIPAA establishes a national privacy floor, medical record disclosure compliance requires consideration of additional federal and state confidentiality laws that may impose more stringent limitations on access, use, redisclosure, consent, or authorization.

Beyond HIPAA: State and Federal Health Information Confidentiality Laws

State Medical Record Confidentiality and Specially Protected Health Information

Multiple legal authorities may afford confidentiality protections that exceed those provided under HIPAA. These include state-specific medical record confidentiality statutes, enhanced protections for mental health treatment records, and federal and state laws governing substance use disorder and alcohol treatment records. Characterizing all patient privacy and health information confidentiality matters as “HIPAA issues” risks disregarding these more nuanced and, in some instances, more protective requirements. In certain circumstances, such oversimplification may result in policies or practices that are legally deficient because they fail to identify and apply the controlling legal standard.

Mental Health Records, SUD Records, HIV/AIDS Information, and Genetic Information

In addition to HIPAA, health information confidentiality is governed by a complex intersection of state and federal law. Many states impose heightened privacy obligations or regulate categories of information not addressed with comparable specificity under HIPAA, including mental health information, HIV/AIDS-related information, and genetic information. Likewise, certain federal regulations, including 42 CFR Part 2, impose particularly stringent consent and disclosure requirements for substance use disorder treatment records. Health care providers, administrators, and compliance personnel must therefore identify overlapping legal obligations and apply the applicable standard that is most protective or otherwise legally controlling.

The following comparison summarizes the principal differences among the confidentiality regimes most relevant to this analysis.

HIPAA, Wisconsin Law, and 42 CFR Part 2 Comparison Table

Legal authorityPrimary scopeGeneral disclosure standardConsent or authorization considerationsCompliance significance
HIPAA Privacy RuleProtected health information held by covered entities and business associates.Establishes a federal privacy floor and permits uses and disclosures when authorized by HIPAA, including for treatment, payment, and health care operations.Authorization is required for certain disclosures, but many routine health care disclosures may proceed without patient authorization when HIPAA permits them.HIPAA is the baseline analysis, but it does not displace more stringent state privacy laws or specialized federal confidentiality rules.
Wis. Stat. § 146.82Wisconsin patient health care records generally.Patient health care records are confidential and may be released only as designated by statute or with informed consent, subject to enumerated exceptions.Informed consent may be required unless a statutory exception applies, including certain treatment, payment, operational, governmental, or court-ordered circumstances.Requires Wisconsin-specific review and may impose obligations distinct from HIPAA for general patient health care records.
Wis. Stat. § 51.30 and Wis. Admin. Code ch. DHS 92Mental health, developmental disability, alcoholism, and drug-dependence treatment records in Wisconsin.Imposes specialized confidentiality requirements for treatment records and limits disclosure except as authorized by statute, regulation, consent, or applicable exception.Written informed consent must generally identify the recipient, subject individual, purpose or need for disclosure, specific information disclosed, effective period, date, and authorized signature.Often requires a more restrictive analysis than general health-record confidentiality rules, particularly for mental health treatment records.
42 CFR Part 2Substance use disorder patient records maintained by federally assisted Part 2 programs and certain recipients of Part 2 records.Historically, Part 2 prohibited use or disclosure unless a regulatory permission applied, patient consent was obtained, or a qualifying court order or other legal basis permitted disclosure. Under the 2024 final rule, a single written consent may authorize future uses and disclosures for treatment, payment, and health care operations, while other uses remain subject to Part 2’s specific limitations.Part 2 now more closely aligns consent content, patient notice, breach-notification, and enforcement provisions with HIPAA. It also permits certain HIPAA covered entities and business associates that receive Part 2 records under a treatment, payment, and health care operations consent to redisclose those records as HIPAA permits, subject to continuing limits on use in proceedings against the patient.Part 2 remains a specialized and highly protective regime, but post-2016 amendments have reduced certain information-sharing barriers while expanding patient rights, breach obligations, and civil enforcement exposure.

Key Compliance Differences for HIPAA, Mental Health Records, and Part 2

HIPAA Baseline Rules and More Protective State Privacy Standards

Several compliance distinctions follow from this HIPAA, Wisconsin law, and Part 2 comparison. HIPAA functions principally as a federal baseline for protected health information rather than as the exclusive or invariably controlling rule for every patient privacy disclosure. Although HIPAA permits many disclosures for treatment, payment, and health care operations, those permissions must be evaluated against any more protective state health information confidentiality law or specialized federal confidentiality requirement. Wisconsin’s general health-record statute requires a separate state-law analysis because patient health care records may be released only as authorized by statute or with informed consent, subject to enumerated exceptions.

Part 2 and Mental Health Record Disclosure Requirements

Third, Wisconsin’s mental health record confidentiality provisions impose a more specialized and often more protective framework than either HIPAA or the state’s general health-record law. Records governed by Wis. Stat. § 51.30 and Wis. Admin. Code ch. DHS 92 require careful review of consent content, disclosure purpose, recipient identity, and any applicable statutory or regulatory exception. Fourth, 42 CFR Part 2 continues to warrant separate analysis whenever substance use disorder treatment information or SUD patient records are implicated. Although post-2016 amendments—particularly the 2020 CARES Act and the 2024 final rule—align certain Part 2 requirements more closely with HIPAA, Part 2 continues to impose specialized consent, redisclosure, proceeding-use, patient-rights, breach-notification, and enforcement requirements that must be evaluated independently.

Patient Privacy Disclosure Triage Before Release

The practical compliance question, therefore, is not merely whether HIPAA permits a disclosure. Rather, the organization must determine the nature of the record, the purpose of the proposed disclosure, the identity and legal status of the recipient, the existence and sufficiency of any consent or authorization, and whether any redisclosure restriction applies. Effective confidentiality compliance accordingly requires a triage process that identifies the applicable legal regime before information is released.

Wisconsin Health Record Confidentiality and HIPAA Harmonization

Wisconsin provides a useful illustration of how this multi-layered analysis operates in practice.

Wisconsin Patient Health Care Records and Mental Health Treatment Records

Wisconsin law illustrates the need for jurisdiction-specific analysis. Wisconsin maintains its own confidentiality statute, codified at Wis. Stat. § 146.82, and also imposes specific requirements governing mental health treatment records under Wis. Stat. § 51.30 and Wis. Admin. Code ch. DHS 92. These provisions may impose requirements that are more restrictive than HIPAA and, in certain respects, more restrictive than Wisconsin’s general patient health care record confidentiality provisions. Historically, Wisconsin’s restrictions on mental health treatment records were sufficiently stringent that disclosure to another treating provider generally required the patient’s written consent.

HIPAA Harmonization Act and Wisconsin Disclosure Workflow

In response to operational challenges created by these heightened restrictions, Wisconsin enacted legislation commonly referred to as the “HIPAA Harmonization Act” in 2013. The legislation modified certain disclosure restrictions and required providers to evaluate, or “triage,” disclosure requests by determining whether HIPAA or more restrictive state confidentiality provisions govern the particular request. This analysis is especially significant when the information at issue consists of mental health treatment records.

Wisconsin HIPAA Harmonization Act: Disclosure Triage Process

Under the Wisconsin HIPAA Harmonization Act, HIPAA standards generally govern disclosures made for treatment, payment, or health care operations. Wisconsin subsequently expanded certain permissible disclosures to narrowly defined emergency circumstances, thereby allowing disclosures to other treating providers when consistent with HIPAA. For disclosures outside treatment, payment, health care operations, or specified emergency circumstances, more restrictive Wisconsin confidentiality requirements may control. Although Wisconsin law contains exceptions permitting disclosure in particular circumstances, those exceptions are generally narrower than the exceptions available under HIPAA.

HIPAA Preemption, More Stringent State Law, and Wisconsin Confidentiality Requirements

HIPAA Preemption and More Stringent State Privacy Law

HIPAA’s preemption framework generally provides that state law is preempted unless the state law is more stringent with respect to privacy protections. In that circumstance, the more stringent state law is not displaced and must be applied. The Wisconsin Harmonization Act, however, identifies categories of disclosures in which HIPAA standards govern notwithstanding otherwise applicable state-law restrictions. Where the Harmonization Act does not make HIPAA controlling, Wisconsin providers must determine whether state law or HIPAA imposes the more restrictive requirement and apply the governing standard.

How to Determine the Governing Confidentiality Standard

For purposes of compliance analysis, preemption should not be treated as a mechanical conclusion. Rather, providers should assess the nature of the record, the purpose of the proposed disclosure, the identity of the recipient, the existence and scope of any patient authorization or consent, and any state-law exception that may apply. This analysis is necessary to ensure that the applicable legal authority is correctly identified and that patient information receives the level of protection required by law.

42 CFR Part 2 Confidentiality Rules for Substance Use Disorder Records

Post-2016 Part 2 Regulatory Updates and the 2024 Final Rule

Among federal confidentiality regimes, 42 CFR Part 2, administered by the Substance Abuse and Mental Health Services Administration (SAMHSA) and enforced in coordination with the U.S. Department of Health and Human Services Office for Civil Rights, remains a specialized framework for substance use disorder treatment records and SUD patient record confidentiality. Since 2016, Part 2 has undergone significant modernization. The 2017 revisions updated terminology and structure, later amendments addressed disclosure mechanics and interoperability concerns, and the 2020 CARES Act directed HHS to align certain Part 2 requirements more closely with HIPAA. The 2024 final rule, effective April 16, 2024, implements that statutory direction, with covered persons required to comply by February 16, 2026.

Single Consent, Redisclosure, and HIPAA Alignment

As revised, Part 2 continues to protect records identifying a patient as having or having had a substance use disorder, but it now permits a single patient consent for all future uses and disclosures of Part 2 records for treatment, payment, and health care operations. When a HIPAA covered entity or business associate receives Part 2 records pursuant to such consent, the recipient may redisclose the information in accordance with HIPAA, subject to Part 2’s continuing prohibitions on use and disclosure in civil, criminal, administrative, and legislative proceedings against the patient absent patient consent or a qualifying court order. The 2024 Part 2 final rule also aligns Part 2 more closely with HIPAA regarding patient notices, breach notification, complaint processes, civil enforcement, and certain patient rights, including accounting-of-disclosure and restriction-request rights. It further recognizes special protections for SUD counseling notes and permits disclosure of de-identified Part 2 records to public health authorities.

Part 2 Compliance Analysis After the 2024 Final Rule

Accordingly, Part 2 compliance should be analyzed under its current framework rather than characterized as a categorical barrier to treatment, payment, or health care operations disclosures. The current substance use disorder record disclosure analysis is more nuanced: organizations must confirm whether the records are Part 2 records, whether a valid treatment, payment, and health care operations consent or another Part 2 permission applies, whether the recipient is a HIPAA covered entity or business associate, whether redisclosure is permitted, and whether any proceeding-use, counseling-note, breach-notification, state-law, or documentation requirement imposes an additional limitation.

Summary of Part 2 regulatory updates: Since 2016, Part 2 has shifted from a more rigid consent-and-disclosure framework toward a modernized structure that better accommodates coordinated care, interoperability, and HIPAA-aligned compliance processes while preserving heightened protections for substance use disorder treatment information. The 2017 revisions updated terminology and structure; subsequent amendments addressed disclosure mechanics and electronic information-sharing concerns; and the 2020 CARES Act directed HHS to align certain Part 2 requirements more closely with HIPAA.

The 2024 final rule implements that alignment by permitting a single written patient consent for future treatment, payment, and health care operations uses and disclosures, modifying redisclosure rules for HIPAA-regulated recipients, and aligning Part 2 more closely with HIPAA regarding patient notices, breach notification, complaint processes, civil enforcement, and certain patient rights. At the same time, Part 2 continues to impose independent restrictions on use or disclosure in civil, criminal, administrative, and legislative proceedings against the patient, absent patient consent or a qualifying court order. The current compliance inquiry therefore remains record-specific and recipient-specific, requiring organizations to determine whether Part 2 applies, whether consent or another permission authorizes the disclosure, whether HIPAA-based redisclosure is available, and whether any remaining Part 2, state-law, counseling-note, breach-notification, documentation, or proceeding-use limitation applies.

Avoiding an Overbroad HIPAA-Centered Compliance Approach

Why an Overbroad HIPAA-Only Approach Creates Compliance Risk

The operative compliance concern is that routine characterization of health information confidentiality issues as “HIPAA issues” may be incomplete from a legal and regulatory perspective. Reliance on generic HIPAA policies, without analysis of state-specific medical record privacy requirements and specialized federal confidentiality regimes, may institutionalize an overbroad HIPAA-centered compliance approach. That approach may expose an organization to compliance risk where applicable law requires a more protective consent, authorization, disclosure, documentation, or redisclosure standard than HIPAA alone would require.

Practical Compliance Recommendations for Patient Privacy Disclosures

Recommended HIPAA, Part 2, and State Privacy Compliance Controls

  • Do not release patient information until the applicable patient privacy law or health information confidentiality regime has been identified and documented.
  • Determine whether the information falls within a specially protected category, including mental health records, substance use disorder records, HIV/AIDS-related information, or genetic information.
  • Identify all potentially applicable federal and state authorities and determine which standard governs the proposed disclosure.
  • Implement consent, authorization, access-control, redisclosure, breach-notification, and proceeding-use safeguards when required by specialized laws, including the post-2024 version of 42 CFR Part 2.
  • Review policies, training materials, and disclosure workflows periodically to ensure they do not reflect an overbroad “HIPAA-only” compliance framework.

Conclusion: Applying the Correct Patient Confidentiality Law

Effective patient confidentiality compliance requires a structured legal analysis that extends beyond HIPAA privacy compliance alone. Although HIPAA establishes an essential federal baseline for the use and disclosure of protected health information, it does not necessarily supply the controlling standard in every circumstance. State medical record confidentiality statutes, specialized mental health record protections, and 42 CFR Part 2 substance use disorder record rules may impose additional, more specific, or more protective requirements depending on the nature of the record, the purpose of the proposed disclosure, the recipient, and the legal authority supporting release. Accordingly, health care organizations should implement a structured confidentiality triage process that requires personnel to identify the applicable category of information, determine all potentially governing federal and state health information confidentiality laws, evaluate the sufficiency of any required consent, authorization, court order, or exception, and document the basis for disclosure before information is released. Policies, training materials, and operational workflows should likewise be reviewed and maintained to ensure that they require legal-regime identification and do not rely on an undifferentiated “HIPAA-only” approach. By embedding this analysis into routine patient privacy disclosure practices, organizations can reduce compliance risk, promote lawful information sharing, and preserve patient trust.


Posted in Compliance Issues, HIPAA - Health Information Privacy, Wisconsin Health Laws | Comments Off on Understanding HIPAA and Its Interaction with State and Federal Confidentiality Laws

Concierge Medicine Legal Guide: Key Compliance and Business Issues for Physicians

What physicians need to know before launching or converting to a membership-based medical practice

As concierge medicine becomes a more common membership-based medical practice model, physicians and practice groups are weighing its potential to improve patient access, reduce burnout, and create more predictable revenue. But launching or converting to a concierge practice requires more than a strong business case. Physicians should evaluate concierge medicine compliance issues early, including fee structure, patient agreements, Medicare strategy, Stark Law and Anti-Kickback considerations, and applicable state-law requirements.

Bottom line: A successful concierge model depends on more than patient demand. Physicians should confirm that their fee structure, patient agreements, Medicare strategy, and state-law compliance approach are sound before launching or converting an existing practice.

Concierge Medicine Models: Choosing the Right Membership Structure

Concierge, retainer-based, and hybrid structures differ in how patients engage with the practice, what services are included, and how fees are designed. Those distinctions affect patient expectations, service obligations, and compliance risk. Clear model selection at the outset helps physicians align the patient experience with the legal and financial realities of the practice.

Patient Panel Size: How Concierge Medicine Changes Care Delivery

Reducing a patient panel from approximately 2,500 patients to 400–600 can improve access, continuity, and physician workload. It also changes how the practice manages patient communications, scheduling, continuity of care, and regulatory oversight. Physicians should plan the transition carefully to avoid unintended gaps in access or service obligations.

Concierge Medicine Compliance: Stark Law, Anti-Kickback, and State Rules

Concierge arrangements can implicate the Stark Law, the Anti-Kickback Statute, Corporate Practice of Medicine rules, and state insurance requirements. Common risk areas include unclear fee structures, poorly defined service commitments, and patient agreements that do not reflect how the model operates in practice. Early legal review can help reduce enforcement risk and support a cleaner launch.

Concierge Practice Business Model: Revenue, Costs, and Patient Experience

Membership-based models may offer more predictable revenue, lower administrative burden, and stronger patient satisfaction. Those benefits depend on realistic financial modeling, disciplined implementation, and a service design that the practice can consistently deliver. The business case should be evaluated alongside the compliance framework, not after it.

Launching a Concierge Medical Practice: Contracts, Fees, and Medicare Strategy

The concierge model is not a simplified version of traditional practice. It is a legally distinct structure that requires precise contract drafting, thoughtful fee design, and a clear Medicare strategy. Physicians should address these issues before launch to support compliance, preserve patient trust, and improve long-term sustainability.

For guidance on fee design, patient agreements, Medicare participation, state-law compliance, or a tailored assessment of your practice’s risks and opportunities, please contact our Healthcare Law team.

Posted in Consierge & Cash-Based Practices, Physician Contracting and Alignment | Comments Off on Concierge Medicine Legal Guide: Key Compliance and Business Issues for Physicians