1. Home
  2. |Insights
  3. |CMS Extends Deadline For Publication of Final Stark II, Phase III Rule

CMS Extends Deadline For Publication of Final Stark II, Phase III Rule

Client Alert | 1 min read | 03.21.07

As expected, CMS announced today that it is extending the timeline for publication of the final rule implementing the Stark Law (the “Phase III Rule”) for one year. With this extension, the interim final rule issued on March 26, 2004 (the “Phase II Rule”) will remain in effect until March 26, 2008, at which time CMS will publish the Phase III Rule.

The timeline for publishing a final regulation cannot exceed three years from the date of publication of the proposed interim final rule, unless there are “exceptional circumstances.” CMS attributes the “numerous and varied” public comments received following publication of the Phase II Rule, as well as the substantial “interagency coordination” among CMS, the Office of the Inspector General, and the Department of Justice, (resulting from their joint authority to enforce the Stark Law), as the justification for the one-year extension.

This leaves unanswered for at least one more year critical and outstanding issues under the Stark Law, including: 1) the Law’s applicability to Medicaid referrals and claims; 2) the potential for expansion of the physician recruitment exception to accommodate certain practical considerations; and 3) the potential narrowing of the in-office ancillary services exception to preclude certain referral practices that are understood to be deemed questionable by CMS.

Insights

Client Alert | 7 min read | 08.17.26

Delayed Notification of Cyberattacks May Trigger HIPAA Breach Notification Rule

After identifying a ransomware attack in 2021, OSF Healthcare System waited until its forensic investigation had concluded before notifying the U.S. Department of Health and Human Services (HHS) — and the affected individuals — of the breach. The 110-day delay (nearly double the 60-calendar-day notification deadline mandated by the HIPAA Breach Notification Rule) triggered an investigation from HHS’s Office for Civil Rights (OCR). The health system’s investigation determined that protected health information (PHI) had been stolen....