Why This Matters
The U.S. Court of Appeals for the Eleventh Circuit recently upheld the constitutionality of the False Claims Act (FCA)'s qui tam provision in U.S. ex rel. Zafirov v. Florida Medical Associates LLC. This decision signals that whistleblower cases under the FCA will continue, emphasizing the need for stronger oversight of your third-party relationships.
If you're managing third-party risk in healthcare, you're on the front line. The qui tam provision allows private citizens to sue on behalf of the government and collect a portion of any recovery. When your vendors submit claims to Medicare or Medicaid, they create FCA exposure for themselves and potentially for you. Whether it's a billing contractor who upcodes or a lab that bundles services improperly, any of these actions can trigger a qui tam action, pulling you into the investigation.
The Eleventh Circuit's decision removes one avenue of challenge that defendants had been testing. Expect more relators to file, not fewer.
What You Need Before Starting
To strengthen your FCA compliance posture, gather these foundational elements:
Your current third-party inventory. Compile a complete list of vendors, contractors, and intermediaries who submit claims to federal healthcare programs on your behalf or under your contracts. Include billing companies, labs, DME suppliers, home health agencies, and any entity involved in government-reimbursed services.
Existing contract language. Review your master service agreements and amendments. Look for compliance clauses, audit rights, certification requirements, and termination provisions tied to regulatory violations.
Your due diligence records. Document the vetting process you used before onboarding each vendor. Include records of their compliance programs, billing accuracy audits, and training records.
Internal reporting channels. Map out how employees and vendors can report suspected false claims today. Identify where reports go, who investigates them, and the response time.
Access to claims data. Review actual billing patterns. Work with your finance and revenue cycle teams to access claims submissions, denials, and adjustments.
Step-by-Step Implementation
Step 1: Segment Your Vendor Population by FCA Risk
Not all third parties carry the same exposure. Create three risk tiers:
High risk: Vendors who submit claims directly to Medicare or Medicaid under your provider number or determine what gets billed.
Medium risk: Vendors who provide clinical services or medical equipment that you bill for but don't control the billing process themselves.
Low risk: Vendors with no connection to government reimbursement.
Focus your next steps on the high-risk tier first.
Step 2: Strengthen Your Vendor Due Diligence Process
For each high-risk vendor, require and document:
FCA-specific training records. Request proof that their billing and clinical staff complete annual FCA training. If they can't produce it, that's a red flag.
Internal audit results. Request their most recent billing accuracy audit. Look for error rates above 5% and ask how they've corrected systemic issues.
Compliance program documentation. They should have written policies on claim submission, upcoding prevention, and bundling rules. Request copies and push back if the policies are generic or outdated.
Whistleblower response protocols. Ask how they handle internal reports of billing irregularities. Document all of this in a vendor risk profile and update it annually, quarterly for your highest-risk relationships.
Step 3: Revise Your Vendor Contracts
Add or strengthen these provisions in your master service agreements:
Explicit FCA compliance representation. The vendor represents and warrants that all claims comply with the FCA, the Anti-Kickback Statute, and the Stark Law.
Audit rights. Retain the right to audit their billing practices, coding accuracy, and claims data with 10 business days' notice.
Immediate disclosure obligation. The vendor must notify you within 48 hours of any government investigation, qui tam filing, or internal discovery of a potential false claim.
Termination for cause. You can terminate immediately if the vendor is named in a qui tam action or fails to cooperate with your audits.
Indemnification. The vendor indemnifies you for any losses, penalties, or legal costs arising from their false claims or FCA violations.
Work with procurement and legal to roll these changes out. Prioritize high-risk vendors for immediate contract amendments.
Step 4: Build an Internal Monitoring Program
Set up quarterly reviews of your high-risk vendors' billing patterns. Look for anomalies that could indicate false claims:
Unusual spikes in claim volume. A 30% increase in claims over two quarters with no corresponding growth in patient volume.
High denial rates. If a vendor's claims are denied at twice the industry average, investigate why.
Frequent use of high-paying codes. If 80% of their claims use the top two reimbursement codes in a category, that's a potential upcoding signal.
Identical claim patterns. Repeated use of the same diagnosis and procedure code combinations across unrelated patients.
Assign someone on your third-party risk team to run these reports. When you spot a red flag, escalate to your compliance officer and the vendor's account manager. Require a written explanation and corrective action plan within 10 business days.
Step 5: Strengthen Your Internal Reporting Channels
Make it easy for employees and vendors to report suspected false claims without fear. Update your Speak-Up Program to include:
Clear FCA reporting pathways. Your hotline intake form should have a specific category for billing fraud and false claims.
Vendor access. External partners need a way to report concerns about your organization or other vendors. Publish your hotline number in vendor onboarding materials and on your compliance website.
Anti-Retaliation Safeguards. Train managers that retaliation against FCA whistleblowers violates federal law and your Standards of Business Conduct.
Fast-track investigation protocols. FCA allegations should trigger an investigation within 72 hours. Assign a senior compliance analyst or external counsel to lead it. Preserve all relevant records immediately.
Validation: How to Verify It Works
After 90 days of implementation, test your new controls:
Run a mock qui tam scenario. Have your compliance team simulate a whistleblower report about a vendor's upcoding. Track how quickly your team identifies the issue, preserves documents, and escalates to leadership.
Audit a sample of vendor files. Pull 10 high-risk vendor profiles. Verify that each contains current FCA training records, audit results, and compliance program documentation.
Review your claims monitoring reports. Confirm that your finance team ran the quarterly billing anomaly checks.
Survey your vendors. Send a brief compliance survey to your top 20 vendors asking whether they're aware of your FCA compliance expectations and your audit rights.
Ongoing Tasks
FCA compliance isn't a one-time project. Build these activities into your annual calendar:
Quarterly claims monitoring. Run your billing anomaly reports every 90 days. Investigate any red flags within two weeks.
Annual vendor recertification. Require high-risk vendors to resubmit their FCA training records, audit results, and compliance program updates every 12 months.
Biannual contract reviews. Every six months, check that your newest vendor contracts include the FCA compliance provisions you drafted.
Annual hotline effectiveness review. Once a year, analyze your FCA-related hotline reports. Report the results to your board or audit committee.
Ongoing legal monitoring. Assign someone to track FCA case law, DOJ enforcement actions, and regulatory guidance. When the government announces a new enforcement priority or settlement, assess whether it affects your vendor population.
The Eleventh Circuit's decision in Zafirov clarifies that qui tam actions will remain a fixture of healthcare enforcement. Your job is to ensure those actions don't start with your vendors.



