
Revenue cycle teams are, as a rule, very good at regulatory compliance. Coding accuracy, payer rules, billing regulations, audit readiness; this is the core discipline RCM is built around. But this is one strong piece of a larger compliance program that also needs privacy, security, and increasingly AI oversight built in alongside it. Some of the largest recent penalties in healthcare haven't come from coding errors at all, and they've instead come from the data and technology sitting underneath the coding and billing function.
Revenue cycle operations sit on an enormous volume of protected health information — diagnoses, procedures, Social Security numbers, financial and insurance data, often aggregated across every patient a practice or health system touches. That makes RCM systems a natural target for attackers. Comstar, a billing and collections company serving more than seventy ambulance services as a business associate, settled with OCR after a ransomware attack went undetected for a week and exposed the ePHI of roughly 585,000 individuals, with OCR citing a failure to conduct an adequate risk analysis. MMG Fusion, a patient-communication software vendor to dental and healthcare practices, settled with OCR after a data breach affecting approximately 15 million individuals, tied to the same core finding: an inadequate risk analysis and a delay in notifying the covered entities it served.
Both companies were business associates. Both failures traced back to the same root cause: an inadequate risk analysis that went unaddressed until a breach forced the issue. Revenue cycle operations run on this same kind of vendor relationship every day, from clearinghouses and billing platforms to patient communication tools and outsourced collections. That means a defined cadence of vendor risk assessments, documentation of each partner's own risk analysis and security practices, and a clear process for acting when a vendor falls short, not a one-time review filed away and forgotten.
AI has moved into the revenue cycle quickly, such as assisted coding, denial-risk scoring, claim scrubbing, and generated appeal narratives, often built directly into billing platforms rather than adopted as standalone tools. In one of the largest False Claims Act healthcare settlements of the past two years, a hospital system paid $23 million to resolve allegations that its automated coding system defaulted emergency department visits to the highest-reimbursement billing code whenever a patient's vital signs were checked more times than the hours they were in the department. It did this regardless of how severe their condition was or what care they received. The government's position was that the automation was matching codes to reimbursement rather than care, and nobody was checking. A parallel pattern is playing out on the payer side. A major insurer is currently in litigation and facing broad court-ordered discovery over allegations that an AI tool was used to predict and drive post-acute care coverage denials with insufficient physician oversight. This presents the same fundamental allegation of an algorithm making a financially consequential decision with the human review that was supposed to sit on top of it wasn't doing its job.
An AI governance program brings all relevant stakeholders into the same review process, so a coding assistant or a denial-prediction tool gets evaluated by people who can see the full picture, not just the department that adopted it. That program defines what the tool is doing, requires a qualified person to review and be able to override its output before its finalized, and monitors the tool's decisions against outcomes on an ongoing basis to catch drift before a regulator or a whistleblower does. Revenue cycle AI doesn't need a separate governance structure from the rest of the organization. It needs a seat inside the one the organization should already be building.
A full RCM compliance program connects billing compliance, privacy, security, and AI oversight into a single coordinated effort rather than parallel ones: current business associate agreements and vendor diligence for every platform and clearinghouse in the chain, a clear picture of where claims data actually flows and who has access to it, security expectations for billing systems and vendors that match the sensitivity of what they hold, and a shared process for evaluating any technology — including AI features — that a vendor adds to the platform. This is additive to the regulatory compliance work already happening, not a replacement for it.
Once a program is built, the next question is whether it actually holds up in practice, and that's best answered by someone outside the team that built it. An independent assessment of RCM compliance that looks not just at coding accuracy but at privacy, AI, and other concerns gives organizations a defensible, third-party view of where the program stands before a payer audit, a regulator, or a whistleblower asks the same question first.
CohesiveIQ helps healthcare organizations build full-picture RCM guardrails — connecting billing compliance with privacy, security, and AI governance — and provides independent assessments to validate they hold up. Contact us to talk through where your RCM operation stands.
.avif)