When ‘Confidential’ isn’t Necessarily Confidential

When ‘Confidential’ isn’t Necessarily Confidential

A client received a letter requesting a wide range of billing and coding information, and copies of variety of medical records before it concluded “please note that data regarding active investigations is classified as confidential and I request that you treat all communication on this matter accordingly.” 

A request from an investigator to keep their contact confidential is quite common, whether it happens in a letter or in an oral communication from a government agent.  The agent has every right to make the request.  From their perspective, the request is smart.  The agents are better off when they can surprise people. 

But it is essential that everyone in your organization understand that it is a request and not a requirement

Why is this distinction so important? 

It has been quite common in my career that as I assist a client responding to an investigation, we discover that someone, be it a current or former employee, learned about the investigation weeks or even months before it was brought to my attention.  Typically, the person who first learned of the investigation took the request for confidentiality to heart, and felt it was improper to tell a compliance officer, legal counsel, or their supervisor about the communication. 

I get it. 

People in the healthcare industry are trained at length about HIPAA and the need to keep a variety of information close to the vest.  We are told that we cannot share information with our spouse, colleagues, or close friends.  In the healthcare world, when someone says keep something confidential, we are trained to listen.  But an investigation is not like medical information.  There is no federal or state law that requires someone who knows about a government investigation to keep the information to themselves.  While I would not recommend it, it is perfectly legal to rent the Goodyear Blimp to fly above a stadium people and declare Glaser Hospital is under investigation.  And while I would not put the message on a dirigible, I do think it should go to the right director.  Whether it is compliance or legal, someone needs to hear about an investigation as soon as it starts. 

Obviously training people about this after the investigation commences is useless.  You need to make sure that your entire organization knows that if they are contacted by a government agent, they should be on the horn to legal or compliance in a matter of minutes.   A well-run healthcare organization has at least annual compliance training. 

I strongly encourage devoting a portion of that training to how to respond when a government agent shows up.  While most healthcare employees will never deal with a government agent, over the course of a decade, most healthcare organizations will have someone in the organization who is interacting with a government agent.  

Whether it’s a police officer looking for a patient or an employee, or a fraud investigator seeking information to pursue a patient or the entity itself, someone in the organization will be dealing with government investigators. 

And since you can’t know who will draw that short straw, you need to train everyone.  Taking five or ten minutes to prepare employees for that eventuality greatly reduces the risk that it will go off the rails. 

Contact from the government is important, and should be taken seriously, but all employees should know that it needn’t be, and shouldn’t be, kept confidential from the compliance and legal team.   

Facebook
Twitter
LinkedIn

David M. Glaser, Esq.

David M. Glaser is a shareholder in Fredrikson & Byron's Health Law Group. David assists clinics, hospitals, and other health care entities negotiate the maze of healthcare regulations, providing advice about risk management, reimbursement, and business planning issues. He has considerable experience in healthcare regulation and litigation, including compliance, criminal and civil fraud investigations, and reimbursement disputes. David's goal is to explain the government's enforcement position, and to analyze whether this position is supported by the law or represents government overreaching. David is a member of the RACmonitor editorial board and is a popular guest on Monitor Mondays.

Related Stories

Leave a Reply

Please log in to your account to comment on this article.

Featured Webcasts

AI, Audits, and the Future of the Revenue Cycle

Artificial intelligence is rapidly transforming healthcare revenue cycle operations, from coding and auditing to compliance and denials. Join industry leaders Pam Warren (MaineHealth) and Raemarie Jimenez (AAPC) for a live fireside chat exploring how AI is changing workflows, workforce roles, payer-provider dynamics, and compliance risk—and what organizations should be doing now to prepare.

June 17, 2026

Trending News

Featured Webcasts

Ask Dr. Hirsch: Clarifying Medicare’s Most Misunderstood Rules – Part 2

Medicare regulations are complex and even seasoned professionals struggle to apply them consistently. Due to overwhelming demand, Dr. Hirsch returns for Part 2 of Ask Dr. Hirsch: Clarifying Medicare’s Most Misunderstood Rules to answer even more of Medicare’s most misunderstood questions, covering inpatient status, observation, SNF access, Medicare Advantage denials, and more. Join Dr. Hirsch as he provides clear, referenced answers to real-world questions submitted by your peers, helping you navigate Medicare compliance with confidence and clarity.

June 18, 2026

Reengineering Utilization Management: Building an Adaptive Model for the New Payer Era

Traditional utilization management models can no longer keep pace with regulatory shifts, payer scrutiny, and operational pressures. In this webcast, Tiffany Ferguson, LMSW, CMAC, ACM, ACPA-C, introduces an Adaptive Model strategy that modernizes UM through role specialization, technology-driven workflows, and proactive, team-based processes. Attendees will learn how to restructure programs to improve efficiency, strengthen clinical collaboration, and enhance financial performance in a rapidly changing healthcare environment.

May 20, 2026

Compliance for the Inpatient Psychiatric Facility (IPF-PPS): Minimizing Federal Audit Findings by Strengthening Best Practices

Federal auditors are intensifying their focus on inpatient psychiatric facilities, using advanced data analytics to spotlight outliers and pursue high‑dollar repayments. In this high‑impact webcast, Michael Calahan, PA, MBA, Compliance Officer and V.P., Hospital & Physician Compliance, breaks down what regulators are really targeting in IPF-PPS admissions, documentation, treatment and discharge planning. Attendees will learn practical steps to tighten processes, avoid common audit triggers and protect reimbursement and reduce the risk of multimillion-dollar repayment demands.

April 9, 2026

Mastering MDM for Accurate Professional Fee Coding

In this timely session, Stacey Shillito, CDIP, CPMA, CCS, CCS-P, CPEDC, COPC, breaks down the complexities of Medical Decision Making (MDM) documentation so providers can confidently capture the true complexity of their care. Attendees will learn practical, efficient strategies to ensure documentation aligns with current E/M guidelines, supports accurate coding, and reduces audit risk, all without adding to charting time.

March 31, 2026

Trending News

Celebrate Lab Week with MedLearn! Sign up to win one year of our Laboratory All Access Pass! Click here to learn more →

Have a Medicare regulation question you’d love Dr. Hirsch to answer? Now is your chance! CLICK HERE to learn more→

Happy National Doctor’s Day! Learn how to get a complimentary webcast on ‘Decoding Social Admissions’ as a token of our heartfelt appreciation! Click here to learn more →

This Memorial Day, we honor those who gave all for our freedom. Take 20% off sitewide through May 29 with code MEMORIAL26 at checkout

CYBER WEEK IS HERE! Don’t miss your chance to get 20% off now until Dec. 1 with code CYBER25

CYBER WEEK IS HERE! Don’t miss your chance to get 20% off now until Dec. 2 with code CYBER24