How to Hire a Health Care Law Attorney
1. Match their clinical and regulatory specialty to your exact health‑care activity
Health‑care law covers many distinct areas, provider compliance (hospitals, physician groups, nursing homes), payer issues (commercial insurers, MA plans), life‑sciences transactions (manufacturer contracting, value‑based arrangements), healthcare transactions (M&A, joint ventures, ambulatory‑care deals), regulatory enforcement (OIG, DOJ, state AG investigations), fraud and abuse (Stark, AKS, False Claims Act), reimbursement and coding appeals, HIPAA/privacy/security, and licensing/credentialing. Tell candidates precisely what you do and which regulators matter (CMS, state Medicaid agencies, OIG, DOJ, FDA for combination products, HHS OCR for privacy). Ask for concrete examples in that same niche, successful RAC/APG appeals, negotiated repayment and corporate‑integrity agreements, Stark/AKS safe‑harbor structuring for payment models, hospital‑physician alignment deals, or HIPAA breach responses, to ensure they understand the specific regulatory frameworks, billing nuances, and enforcement risk profiles that apply to your operations.
2. Verify technical team, compliance playbooks, and rapid‑response enforcement capabilities
Health‑care matters require multi‑disciplinary teams and fast action. Ask who they routinely engage, coding and billing experts, reimbursement consultants, clinical advisors, IT/security forensics, and external auditors, and request sample deliverables: compliance program manuals, internal‑audit reports, HIPAA risk‑assessment templates, and mock OIG‑self‑disclosure packages. Confirm they have a documented enforcement playbook for investigations: preservation and privilege protocols, prompt restitution and voluntary disclosure strategies (OIG‑self‑disclosure, voluntary refund), negotiation approaches for settlement and CIA terms, and experience managing parallel state Medicaid audits or qui tam suits. For privacy incidents, ensure they coordinate forensic data collection, breach‑notification timing (state and HHS OCR), and mitigation steps that limit regulatory penalties and civil exposure. Practical compliance tools and an established incident‑response routine prevent small problems from escalating into expensive enforcement actions.
3. Require a written engagement with phased fees, risk‑allocation advice, and operational integration for compliance and transactions
Get an engagement letter that specifies scope (compliance program design, transactional documentation, enforcement defense, or ongoing regulatory counsel), phased deliverables, and fee structure tied to stages, flat fees for discrete tasks (policy drafting, HIPAA risk assessment), capped budgets for enforcement response, and predictable retainers for ongoing counsel. Insist on explicit allocation of third‑party costs (forensic vendors, coding audits, expert witnesses) and pre‑approval thresholds. Require operational integration: the attorney should provide implementation checklists (training modules, audit schedules, reporting templates), point‑of‑contact rules for investigations, and coordination mechanisms with finance, clinical leaders, and IT. Finally, demand written remediation and monitoring plans if compliance gaps are found (corrective‑action timelines, performance metrics, and periodic reporting) and a dispute/enforcement playbook that maps probable outcomes and appeal paths, these concrete commitments align legal advice with clinical operations and limit regulatory, financial, and reputational risk.