LTCPro

Financial Compliance Pitfalls in Skilled Nursing

Digital transformation is a journey, not a destination, and 2024 is poised to be another promising chapter, continuing the breakthrough trends we have

In November 2025, HHS-OIG audited a single New York skilled nursing facility and recommended it repay $31.2 million in improper Medicare payments, the first audit in a new, ongoing series targeting SNFs under PDPM. Here’s what’s actually driving compliance risk into 2026, and what closes the gap.

By: Paul Mason, Director of Strategic Partnerships at LTCPro

For: SNF and ALF administrators, CFOs, and compliance officers responsible for Medicare billing accuracy, staffing reporting, and HIPAA compliance.

Key Takeaway: Financial compliance in skilled nursing spans five connected risk areas, billing accuracy, fraud exposure under the False Claims Act, documentation, staffing reporting, and data security, and a failure in one routinely becomes evidence in another. HHS-OIG’s new PDPM-focused audit series, opened in late 2025, is the clearest sign yet that regulators are treating these as one connected system, and facilities should too.

Table of Contents

Financial compliance is a critical part of operating a skilled nursing facility. Medicare, Medicaid, the Office of Inspector General (OIG), and the Centers for Medicare & Medicaid Services (CMS) all enforce compliance rules that carry real financial consequences: fines, reimbursement denials, fraud investigations, and reputational damage that follows a facility long after a settlement is signed.

The stakes are not theoretical. In November 2025, HHS-OIG opened a new, ongoing audit series specifically targeting SNF billing under the Patient-Driven Payment Model. The first facility it reviewed, a New York SNF, was flagged for $31.2 million in improper payments tied to inaccurate coding, insufficient medical necessity documentation, and noncompliant records. (Bryan Cave Leighton Paisner, False Claims Act: Recent Updates, December 2025) This guide walks through the five financial compliance pitfalls actually driving enforcement right now, backed by real, current cases, and what genuinely reduces exposure in each area.

Common Financial Compliance Pitfalls in Skilled Nursing

1.1 Billing & Coding Errors

Errors in billing and coding remain among the most frequent sources of compliance violations in SNFs. Incorrect PDPM coding, upcoding, duplicate billing, and missing documentation all put claims at risk of denial and, increasingly, formal audit scrutiny.

The clearest current example is the HHS-OIG PDPM audit series itself. The November 2025 audit that flagged $31.2 million in improper payments named inaccurate coding as a root cause, and OIG confirmed this was the first in an ongoing series, not a one-time review. (Bryan Cave Leighton Paisner)

Best Practices:

  • Audit PDPM-coded claims quarterly, not just when a denial or an audit forces the review.
  • Add a documented second-review step on PDPM classification before the MDS locks, since misclassification is the specific gap OIG’s new audit series is built to catch.
  • Use claims-scrubbing software to flag coding mismatches before submission, and treat it as a supplement to trained staff judgment, not a replacement for it.
1.2 Fraud & False Claims Act Violations

The False Claims Act (FCA) penalizes facilities that submit false claims to government healthcare programs, and it does not require proof of intent to defraud: liability attaches if a facility knew, or reasonably should have known, that a claim was false. Whistleblower lawsuits, not just routine audits, are an active enforcement channel.

In early 2026, three affiliated skilled nursing facilities in Illinois agreed to pay $300,000 to resolve FCA allegations that they billed for medically unnecessary rehabilitation services, a case that originated from a whistleblower lawsuit filed under the FCA’s qui tam provisions. (U.S. Department of Justice, Office of Public Affairs) Separately, HHS-OIG settled with 19 skilled nursing facilities for a combined $1,565,374 in May 2025 over allegations that they employed individuals excluded from federal healthcare programs. (HIPAA Journal)

Best Practices:

  • Screen every new hire, contractor, and vendor against the OIG List of Excluded Individuals and Entities before they touch billing or resident care.
  • Re-screen on a recurring basis, not just at hire, since a staff member can become excluded after they’re already on payroll.
  • Maintain an anonymous internal reporting channel, since a meaningful share of FCA cases nationally originate from whistleblowers rather than external audits.
1.3 Inadequate Documentation & Medical Necessity Issues

CMS requires documentation detailed enough to independently justify that skilled nursing and rehabilitation services were medically necessary, not just that they were clinically provided. This is the pitfall that connects most directly to the others: OIG’s own November 2025 audit named “lack of medical necessity verification” and “noncompliant documentation practices” as root causes alongside coding errors, not as a separate issue. (Bryan Cave Leighton Paisner)

Best Practices:

  • Ensure documentation stands on its own, meaning a reviewer shouldn’t need to infer medical necessity from surrounding context.
  • Review documentation practices against HHS-OIG’s November 2024 nursing facility compliance program guidance, not an internal checklist that predates it.
  • Conduct documentation audits on a recurring schedule, tied to the same cadence as PDPM coding reviews, since the two are rarely separate problems in practice.
1.4 Payroll-Based Journal (PBJ) Reporting Errors

Under CMS rules, SNFs must submit quarterly Payroll-Based Journal reports to verify staffing levels. Incorrect or missing reports carry consequences that hit fast: a missed or late PBJ submission triggers an automatic one-star staffing rating under CMS’s Five-Star system, regardless of a facility’s actual staffing levels, and that penalty is separate from any additional enforcement tied to genuine understaffing. Facilities found in violation at the immediate jeopardy level can face civil monetary penalties of $8,500 to $10,000 per day. (Fingercheck, What is Payroll-Based Journal Reporting?)

This matters more, not less, heading into 2026. CMS repealed the federal minimum staffing mandate (the 24/7 RN requirement and minimum hours-per-resident-day standard) effective February 2, 2026, but PBJ reporting itself was not part of that repeal and remains mandatory every quarter. CMS also began auditing VBP and QRP data across roughly 1,500 randomly selected facilities, about 10% of all certified providers, starting in January 2026. (Netchex, Nursing Home Payroll Compliance in 2026)

Best Practices:

  • Pull PBJ data from a single, reconciled payroll source rather than compiling it across systems that don’t talk to each other, which is consistently where reporting errors originate.
  • Verify staffing data against actual payroll and timekeeping records before submission, not after a discrepancy is flagged.
  • Don’t assume the 2026 staffing mandate repeal reduced PBJ scrutiny. It didn’t.
1.5 HIPAA & Data Security Breaches

Failing to protect patient data under HIPAA can result in civil monetary penalties, corrective action plans, and reputational damage that outlasts the settlement itself. Penalties in 2026 range from $145 to just over $2.19 million per violation, depending on the level of culpability OCR determines, and OCR closed 21 settlements in 2025, one of its busiest enforcement years to date. (HIPAA Journal, What Are the Penalties for HIPAA Violations? 2026 Update)

Nursing facilities are not a protected category from this scrutiny. HHS’s Office for Civil Rights imposed a civil monetary penalty on a New Jersey nursing facility specifically for failing to provide timely access to patient records, and a nursing facility operator was fined in September 2025 for violations of the HIPAA Privacy and Breach Notification Rules. (HHS.gov, Resolution Agreements)

Best Practices:

  • Conduct and document a current HIPAA risk analysis, since OCR has increasingly tied enforcement specifically to facilities that never completed one, independent of whether a breach occurred.
  • Don’t treat HIPAA risk as purely a cybersecurity issue. The New Jersey enforcement action above was about delayed record access, not a data breach.
  • Train staff on both data security and patients’ right of access, since OCR enforces both tracks actively.

Get a compliance exposure review. LTCPro will walk through your PDPM coding, documentation, and PBJ workflows against current OIG and CMS audit criteria, at no cost.

Request a Compliance Review →

How LTCPro Helps SNFs Manage Financial Compliance

Financial compliance breaks down when billing, documentation, payroll, and oversight live in five disconnected systems with no one checking how they fit together. LTCPro’s revenue cycle management, billing and accounts receivable, and back-office services are built specifically for skilled nursing and assisted living facilities across the United States, backed by proprietary software covering financial, clinical, and management functions in one place.

2.1 PDPM Billing & Coding Support

LTCPro’s billing and accounts receivable service handles PDPM-coded claim submission for Medicare Part A, giving facilities a dedicated billing team reviewing coding accuracy before claims go out, not a single generalist carrying the full compliance burden alone.

Facilities can pair LTCPro’s proprietary software with in-house or LTCPro back-office staff, so PDPM classification gets a second set of eyes before the MDS locks, which is exactly where HHS-OIG’s current audit series is finding the most error.

2.2 Revenue Cycle Oversight Built for Compliance, Not Just Collections

LTCPro’s revenue cycle management service tracks claims from submission through resolution, giving administrators ongoing visibility into denial patterns and aging accounts receivable instead of discovering problems only at audit time.

Because billing and accounts receivable run through the same system, facilities get one consistent view of claim status rather than reconciling numbers across separate software.

2.3 Documentation That Lives in One System, Not Five

LTCPro’s software integrates financial, clinical, and management data, so documentation supporting a claim’s medical necessity sits alongside the billing record it supports, rather than in a separate system a biller has to cross-reference by hand.

This structure is designed to reduce exactly the kind of disconnect between clinical documentation and billed claims that shows up repeatedly in OIG’s PDPM audit findings.

2.4 Payroll & Staffing Data Management

LTCPro’s payroll management service handles payroll processing for SNFs and ALFs, giving facilities a single, reconciled source of staffing data rather than compiling PBJ submissions across payroll, timekeeping, and scheduling tools that don’t talk to each other.

A single source of payroll truth is the most direct way to prevent the kind of PBJ reporting errors that trigger an automatic staffing-rating penalty, regardless of a facility’s actual staffing levels.

2.5 Back-Office Financial Accuracy Across the Full Facility

LTCPro’s accounts payable and bookkeeping and general ledger services extend the same documentation discipline to the rest of the facility’s financial operations, not just resident billing, so financial records stay audit-ready across the board.

Facilities can license LTCPro’s software independently or combine it with LTCPro’s back-office staffing, choosing the model that matches whether their compliance gap is a systems problem or a staffing capacity problem.

2.6 HIPAA-Compliant Data Handling

LTCPro maintains HIPAA compliance across its billing, revenue cycle, and back-office services, consistent with the standard every business associate handling resident PHI is required to meet.

Keeping financial, clinical, and management data in one proprietary system, rather than scattered across separate tools, reduces the number of places PHI has to move between vendors, which is itself a common source of exposure under HIPAA’s Security Rule.

Talk to LTCPro about your facility’s compliance exposure. A short conversation to find out where your current process leaves you exposed before an auditor finds it first.

Schedule a Conversation →

Where Financial Compliance in SNFs Is Headed

Regulatory scrutiny of SNF financial compliance is intensifying, not easing, heading into 2026:

Expanded, targeted audit programs. HHS-OIG’s PDPM audit series, opened in November 2025 with the first facility flagged for $31.2 million, is explicitly structured as an ongoing program rather than a single review, signaling more SNFs will be selected in the series that follows.

Increased data-driven staffing and quality auditing. CMS’s move to audit VBP and QRP data across roughly 10% of certified SNFs in 2026 shows compliance monitoring shifting from periodic surveys toward continuous, data-driven review.

HIPAA enforcement staying active regardless of breach status. OCR’s 2025 enforcement pace, one of its busiest years on record, and its willingness to penalize facilities for documentation gaps like a missing risk analysis, not only for confirmed breaches, means passive compliance postures carry more risk than they used to.

Key Takeaways:

  • HHS-OIG’s new PDPM audit series makes billing and coding accuracy an active, ongoing risk area, not an annual checklist item.
  • False Claims Act liability does not require intent to defraud, which makes documentation quality a legal safeguard as much as a billing one.
  • Medical necessity documentation is the thread connecting billing errors, FCA exposure, and OIG audit findings, it rarely stays contained to one department.
  • PBJ reporting remains mandatory and under increased CMS scrutiny in 2026, even after the federal staffing mandate repeal.
  • HIPAA enforcement against nursing facilities is active and not limited to data breaches; documentation and access failures are also enforced.
  • If your facility hasn’t reviewed its compliance program against current OIG guidance in the past year, that’s the first gap worth closing.

FAQ

What triggers an OIG audit of a skilled nursing facility?

HHS-OIG selects facilities for audit based on billing data patterns, prior compliance history, and targeted program-wide initiatives, such as the PDPM audit series launched in November 2025. A facility does not need a prior complaint against it to be selected for this kind of systematic review.

Can a SNF face False Claims Act liability without intending to defraud Medicare?

Yes. The FCA standard is met if a claim was false and the facility knew, or reasonably should have known, that it was false. This is a lower bar than fraud, and it’s why documentation that doesn’t independently support medical necessity creates legal exposure even when the underlying care was appropriate.

Does PBJ reporting still apply after the 2026 staffing mandate repeal?

Yes. CMS repealed the federal 24/7 RN requirement and minimum hours-per-resident-day standard effective February 2, 2026, but Payroll-Based Journal reporting was a separate requirement and remains mandatory every quarter, with CMS auditing this data more actively in 2026, not less.

How much can a HIPAA violation actually cost a nursing facility?

Civil monetary penalties range from $145 to just over $2.19 million per violation as of 2026, depending on the culpability level OCR assigns. Nursing facilities have been penalized both for data security failures and for delayed patient record access.

How often should a SNF review its compliance program against current OIG guidance?

At minimum, annually, and immediately after a significant guidance update, such as the nursing facility compliance program guidance HHS-OIG issued in November 2024. A program built against outdated guidance can create a false sense of security while leaving real gaps unaddressed.

LTCPro provides revenue cycle management, billing, and back-office support for skilled nursing and assisted living facilities across the United States, pairing proprietary software with hands-on staffing support.

Author Bio
Paul Mason
Paul Mason

Director of Strategic Partnerships at LTCPro, with over 20 years of experience in long-term care revenue cycle management. Shares insights on AI-driven billing solutions to help skilled nursing and assisted living facilities reduce denials and strengthen financial performance.