Resources

Client Alerts, News Articles, Blog Posts, & Multimedia

Everything you need to know about BMD and the industry.

FAQs:  Administrative Fees Under Medicare

Client Alert

Late patients, last-minute cancellations, and difficulty in collecting fees are all common complaints from our healthcare clients.  As such, it is no wonder that a common topic among our healthcare clients revolves around what administrative fees can be charged to patients and related issues.  We thought it would be interesting to share some of the most frequently asked questions we receive in this area. 

Please note that this article is not legal advice, and readers are advised to seek legal counsel concerning their specific facts and circumstances.  All answers are based on Medicare laws and regulations.  Many commercial payers will follow Medicare guidelines in their own policies, but a provider will need to check with each specific commercial payer to confirm their policies.  Additionally, practices that are “cash-pay only” would not be subject to Medicare regulations or commercial payer policies, because they don’t bill third-party payers.  Finally, every state has unique laws, so it is imperative to confirm whether your state law addresses any of these topics. 


Q1: Can a physician practice require patients to pay a deposit for an appointment or scheduled procedure?

        A: Yes, practices can require deposits in order to secure appointments. However, some insurers may explicitly forbid your practice from doing so. Additionally, best practice is to inform patients upfront about the fee.


Q2: What about hospitals? Are they permitted to collect deposits?

        A: Chapter 2 (Section 10.3) of the Medicare Claims Processing Manual does not permit requiring prepayment as a condition of admission. However, Section 10.4 does state that “[t]he provider may collect deductible or coinsurance amounts only where it appears that the patient will owe deductible or coinsurance amounts and where it is routine and customary policy to request similar prepayment from non-Medicare patients with similar benefits that leave patients responsible for a part of the cost of their hospital services.”

 

Q3: Can my physician practice charge appointment cancellation fees to patients who do not cancel within 24 hours of their appointment?

        A: Yes, charging a fee is permitted by Medicare if it is in the practice’s written policy. However, Medicare is clear that these late fees can be charged ONLY to Medicare patients, and Medicare will not pay for the missed appointment, so it must be charged to the patient directly.

 

Q4: Can hospitals charge hospital inpatients a missed appointment fee?

        A: No, this would violate 42 CFR 489.22.

 

Q5: Can my practice keep patient credit cards on file?

        A: Yes, practices can keep patient credit cards on file, provided that certain safeguards are put in place to protect card information. Additionally, you should check with your credit card processing company to assure that they permit cards to be kept on file, as well as check with any applicable insurance carriers that would cover identity theft, credit card fraud, or other issues involving the practice’s credit card transactions.

 

Q6: What requirements does my physician practice need to follow in order to safeguard patient credit card information?

       A: Both the Payment Card Industry Data Security Standard (“PCI DSS”) and the Health Insurance Portability and Accountability Act (“HIPAA”) apply to practices that store patient credit card information. As such, practices should have a policy in place outlining the requirements for each.

PCI DSS lists twelve (12) safeguards that must be met when storing credit card information:

(1) Install and maintain a firewall configuration to protect cardholder data;

(2) Will not use vendor-supplied defaults for system passwords and other security parameters;

(3) Protect stored cardholder data;

(4) Encrypt transmission of cardholder data across open, public networks;

(5) Use and regularly update anti-virus software or programs;

(6) Develop and maintain secure systems and applications;

(7) Restrict access to cardholder data by business need to know;

(8) Assign a unique ID to each person with computer access;

(9) Restrict physical access to cardholder data;

(10) Track and monitor all access to network resources and cardholder data;

(11) Regularly test security systems and processes; and

(12) Maintain a policy that addresses information security for all personnel.


Additionally, HIPAA lists certain standards for disposing of patient payment information. For example, safe disposal would include card information being placed into locked shred bins, and all employees who are responsible for disposing of such information receive training in proper disposal.

If you have questions about rules or policies governing administrative fees charged to patients, please contact Member and General Counsel Jeana Singleton by email at jmsingleton@bmdllc.com, by phone at (330) 253-2001 or another member of the Healthcare & Hospital Law Department of Brennan Manna & Diamond.

 


RNs and APRNs Take Note: Ohio Board of Nursing Mandates a New CE Reporting Period

Ohio’s Board of Nursing has updated the continuing education reporting period for RNs and APRNs. Beginning March 26, 2026, CE credits must be completed between July 1 and June 30 of odd-numbered years, replacing the previous November to October timeframe.

Ohio Med Spas: Peptide Do's and Do Not's

Recent guidance from the Ohio Board of Pharmacy outlines key compliance requirements for med spas using peptides. While some peptide drugs are FDA approved, others are not or cannot be compounded. Med spa operators should ensure they source medications from licensed suppliers, avoid non-approved or “research use only” products, and follow all compounding and storage regulations to maintain compliance and avoid enforcement actions.

Substance Use Disorder Providers: 42 CFR Part 2 Now Enforceable

Updates to 42 CFR Part 2 are now enforceable, bringing significant changes to how substance use disorder (SUD) records are handled. The Final Rule aligns Part 2 more closely with HIPAA, introduces updated penalties, allows a single patient consent for treatment, payment, and operations, and adds new requirements for Notices of Privacy Practices. It also creates a formal definition of SUD counseling notes and imposes strict consent requirements for their use and disclosure. Providers should review and update policies to ensure compliance.

AAA Introduces AI-Assisted Arbitrator for Certain Disputes

The American Arbitration Association has introduced an AI-assisted arbitration platform designed to streamline certain document-based disputes. While a human arbitrator still makes the final decision, the technology can improve efficiency, reduce costs, and accelerate case resolution. Companies should weigh these benefits against considerations such as transparency, risk, and contractual requirements before adopting AI-assisted arbitration.

Quiet Hours Texts and TCPA Claims: Consent Remains King as Courts Divide on Text Messages

Businesses face increasing TCPA lawsuits over off-hours marketing texts, but recent court decisions highlight strong defenses. Clear consumer consent and updated terms and conditions can defeat many claims, while a growing number of courts are finding that text messages are not “telephone calls” under the statute. Proactive compliance measures, including clickwrap agreements and forum-selection clauses, are critical to reducing risk.