
Complete Z72.0 Coding Guide for Behavioral Health Billing
September 22, 2026
How to Use H0001 Code for Behavioral Health Screening Services
September 23, 2026Are Billing Mistakes Costing Your Behavioral Health Practice Thousands? Here's How to Stay Compliant

Behavioral health denial rates run nearly double the medical benchmark. A 2026 study found behavioral health denial rates at 11.8 percent, nearly twice the rate for general medicine . The root cause is rarely clinical competence. It is the compliance gap between what happened in the session and what the payer sees.
Medical billing compliance in behavioral health is not a back-office function. It is a set of legal obligations, documentation standards, and enforcement risks that determine whether services get paid. This guide breaks down what those obligations are, who enforces them, and what California providers specifically need to watch. Medical Billing Compliance affects every part of the revenue cycle.
What Medical Billing Compliance Actually Means
Compliance is not one thing. It is four overlapping sets of rules, each with different enforcers and different consequences. Medical Billing Compliance applies across each of these overlapping regulatory layers.
The four compliance layers
|
Layer |
What it governs |
Primary enforcer |
|
HIPAA and 42 CFR Part 2 |
Privacy and security of patient records |
HHS Office for Civil Rights |
|
False Claims Act and Anti-Kickback Statute |
Billing integrity and referral relationships |
HHS OIG and DOJ |
|
Payer-specific billing rules |
Covered codes, modifiers, authorization |
Commercial payers and Medi-Cal |
|
State Medicaid requirements |
Enrollment, documentation, routing |
California DHHS and county systems |
A practice can be perfectly compliant with one layer and exposed on another. A clinician who documents thoroughly but bills for an excluded employee violates the False Claims Act regardless of note quality. A practice that follows CPT guidance but ignores Blue Shield modifier requirements creates denials despite clinical accuracy.
The compliance question is not “did we follow the coding rules.” It is “can we prove we followed every rule that applies to this claim.” Medical Billing Compliance requires proof across all applicable rules.
HIPAA Compliance for Behavioral Health
Behavioral health creates HIPAA challenges that general medical practices do not face. The residential nature of many programs, the group therapy model, and the sensitivity of mental health and substance use records all increase exposure. Medical Billing Compliance also depends on protecting the patient information connected to each claim.
The most common violations in behavioral health settings
- Unauthorized disclosures in group settings. Staff discussing specific patients in hallways or common areas. Patients seeing other patients’ records during group check-in .
- Improper disposal of records. Paper records with PHI placed in regular trash or recycle bins. Electronic media not properly wiped .
- Insufficient access controls. Front desk staff with access to clinical progress notes. Billing specialists with access to psychotherapy notes. A single EHR access level for all staff .
- Missing Business Associate Agreements. No BAA with the EHR vendor, billing company, clearinghouse, IT support firm, shredding service, or cloud provider .
- Failure to conduct risk assessments. OCR has consistently identified missing or inadequate risk assessments as a top enforcement priority .
- Unencrypted communications. Staff texting about patients on personal phones. Emailing PHI without encryption. Using consumer messaging apps for clinical communication .
HIPAA penalty structure
|
Culpability level |
Per violation |
Annual maximum |
|
Did not know |
$145 to $73,011 |
$25,000 |
|
Reasonable cause |
$1,461 to $73,011 |
$100,000 |
|
Willful neglect, corrected |
$14,602 to $73,011 |
$250,000 |
|
Willful neglect, not corrected |
$73,011 |
$1,500,000 |
The difference between tier 1 and tier 4 is not the violation itself. It is whether the practice had a compliance program, conducted risk assessments, trained staff, and documented its efforts. Medical Billing Compliance requires those efforts to be documented.
OIG Enforcement: Exclusions, Kickbacks, and the Compliance Program
The HHS Office of Inspector General enforces federal fraud and abuse laws. Three areas create the most risk for behavioral health providers. Medical Billing Compliance is directly affected by OIG enforcement requirements.
The exclusion list is non-negotiable
Federal law prohibits paying individuals or entities excluded from federal healthcare programs. If a practice employs an excluded individual, even unknowingly, civil monetary penalties can reach approximately $100,000 per item or service that excluded person provided .
The requirement is straightforward and commonly mismanaged. Screen all employees, contractors, and vendors against the LEIE before engagement and on a regular ongoing basis. Monthly screening is the OIG standard and is required by many state Medicaid programs. A New Hampshire telehealth mental health provider paid $300,000 to resolve allegations that it billed Medicaid for services provided by an excluded individual.
The Anti-Kickback Statute reaches referral relationships
The Anti-Kickback Statute prohibits exchanging anything of value to induce or reward referrals for services covered by federal programs. In behavioral health, enforcement activity has focused on:
- Patient brokering, paying third parties for referrals
- Providing free housing, transportation, or other benefits to attract clients covered by insurance or public programs
- Incentive programs that reward patients for attending sessions
A Clifton Park telehealth company admitted that an incentive program offering $25 gift cards to patients after attending therapy sessions violated the Anti-Kickback Statute.
The seven elements of an effective compliance program
The OIG outlines seven core elements. Having a functioning program does not immunize a practice from enforcement, but it can significantly mitigate penalties if issues are discovered .
- Written policies and procedures
- Designation of a compliance officer
- Training and education
- Auditing and monitoring
- Reporting mechanisms
- Enforcement of standards
- Corrective action
The Clifton Park telehealth settlement included an admission that the company’s compliance program failed to meet statutory requirements for billing oversight, compliance monitoring, and training . The absence of a functioning program turned a billing problem into a settlement. Medical Billing Compliance must therefore include active oversight.
Documentation and Medical Necessity: The Audit Battleground
Payers are more stringent on the medical necessity review of behavioral health than for most medical specialties. The documentation should be able to explain what happened, why it was needed, and how it relates to the treatment plan. Medical Billing Compliance depends heavily on documentation that supports each submitted claim.
What auditors check
- Start and stop times on time-based codes
- Specific interventions linked to treatment plan goals
- Evidence of medical necessity with concrete symptom descriptions
- Rendering clinician signature that matches the claim
- Active treatment plans with review dates and signatures
The documentation failures that recur
An OIG review of psychotherapy services found that for 128 of 216 sampled enrollee days, clinicians did not meet Medicare requirements, most often because psychotherapy time was not documented. For another 54 days, clinician signatures were missing .
The failures are administrative, not clinical. Missing signatures. Unspecified treatment frequency. Notes that do not connect the intervention to the treatment plan. Medical Billing Compliance becomes especially important when documentation is reviewed by payer systems.
Why payer AI changes the stakes
Payers are expanding AI-driven audit activity, using claims data analysis at scale to identify outliers and focusing chart review where the data suggests risk. With LLM technologies, payers can review documentation comprehensively and efficiently against payer-specific rules .
Manual sampling cannot keep pace. Practices relying on retrospective chart review are using a process that was not built for payer AI at scale.
The time code rule
Psychotherapy codes 90832, 90834 and 90837 are not based on the length of the session. Medical Billing Compliance also applies to accurate psychotherapy time reporting.
- 90832: 16 to 37 minutes
- 90834: 38 to 52 minutes
- 90837: 53 minutes or more
The 53-minute floor for 90837 comes from the CPT midpoint rule. A 50-minute session billed as 90837 is the single most audited upcoding pattern in behavioral health.
Utilization Review and Prior Authorization Compliance
Utilization reviews are essentially repetitive prior authorizations for a continuous treatment episode. They are routine for behavioral diagnoses that require ongoing treatment. Medical Billing Compliance continues throughout utilization review and authorization processes.
Why UR creates compliance risk beyond denials
Because authorizations are ongoing, they create a recurring obligation to justify medical necessity throughout care episodes. IOP, PHP, and residential admissions must align at each reauthorization with level of care guidelines for the diagnosis.
Each reauthorization is a point where the documentation record can break. Once a care episode closes, revenue that was not authorized cannot be recovered.
The documentation burden is substantial
A 2025 study found that 92 percent of medical groups have hired or reassigned staff to manage prior authorizations . For behavioral health, authorization volume grows in direct step with patient volume. Each new admission requires intake documentation and ongoing reviews. Medical Billing Compliance must account for these recurring authorization requirements.
Regulatory changes in 2026
The Interoperability and Prior Authorization rule compresses payer decision timelines to 72 hours for urgent requests and seven days for standard requests. Payers must include specific reasons for denying authorizations. Quicker cycles do not necessarily mean easier processes for behavioral health organizations. The documentation requirements remain the same.
California-Specific Compliance Requirements
California adds a distinct layer of regulatory complexity. Medi-Cal behavioral health services route through multiple systems, each with different authorization and billing requirements. Medical Billing Compliance in California must account for these different billing systems.
Who handles what in California
|
Service type |
Authorization owner |
Billing route |
|
Specialty mental health services |
County mental health plan |
County system |
|
Drug Medi-Cal (DMC-ODS) |
County SAPC |
State DMC billing system |
|
Non-specialty mental health |
Medi-Cal managed care plan |
Plan-specific |
|
Commercial behavioral health |
Commercial payer |
Payer-specific |
The routing error problem
Billing SUD services to a Medi-Cal managed care plan when they should be billed through the county DMC-ODS system is a leading cause of claim denials for SUD providers in California. The multi-system architecture makes routing errors common for providers new to a county market. Medical Billing Compliance requires the correct routing before claims are submitted.
CalAIM documentation changes
California Advancing and Innovating Medi-Cal (CalAIM) has restructured documentation requirements for specialty mental health, DMC, and DMC-ODS services. The updated standards, effective January 1, 2024, align with CMS national coding standards and physical health care documentation practices .
Required Claim trainings for all behavioral health clinical staff cover foundations of documentation, assessment, progress notes, care coordination, and coding . New staff must complete required training within 90 days of hire. Medical Billing Compliance therefore includes California-specific training requirements.
Commercial payer conflicts
Blue Shield of California implemented policies requiring modifier 25 on psychotherapy add-on codes when billed with E/M services. The California Medical Association has formally urged Blue Shield to rescind these policies, warning they create administrative burden and may impede integrated behavioral health care. Medical Billing Compliance must also account for payer-specific billing policies.
Credentialing timeline changes
In October 2025, California AB 1041 was signed into law, which mandates that Department of Managed Health Care (DMHC)-regulated plans must either approve a completed credentialing application or provisionally approve the provider within 90 days, or within 120 days if they will not approve the completed application. The core requirement will go into effect 01/01/2027. Medi-Cal managed care is exempt.
Enforcement Examples: What Non-Compliance Costs
The consequences of compliance failures are not theoretical. Behavioral health providers have paid substantial settlements for billing and documentation violations. Medical Billing Compliance failures can create significant financial exposure.
Clifton Park telehealth company: $300,000
Aptihealth admitted responsibility for billing Medicare and Medicaid for appointments that did not occur because the patient was a no-show, billing for responses to patient messages without regard to whether the communications involved billable clinical content, and billing for psychological testing services that were not sufficiently documented. The company also implemented an incentive program providing $25 gift cards to patients after attending therapy sessions, which the government contended violated the Anti-Kickback Statute.
New Hampshire telehealth provider: $300,000
LifeWorks Counseling Associates and its owner paid $300,000 to resolve allegations that they submitted claims to Medicaid for services provided by an individual excluded from federal healthcare programs. A provider excluded from being paid to give healthcare for reasons including prior fraud, criminal convictions, or patient abuse cannot have services billed to federal programs.
Massachusetts ABA provider: up to $778,703
Flexible Fundamentals and its co-owners settled allegations that they billed MassHealth for ABA services never provided and/or not properly documented, and for failing to provide adequate supervision of paraprofessional behavioral technicians. The settlement required the owners to implement compliance and monitoring programs for three years, with independent compliance monitors conducting annual on-site audits.
Medical Billing Compliance failures in these cases were tied to administrative breakdowns. The pattern across these cases is consistent. The violations were administrative. The penalties were substantial. The presence or absence of a compliance program determined the severity of the outcome.
Building a Compliance Program That Works
A compliance program is not a binder. It is a set of operating practices that prevent violations and produce evidence when needed. A strong Medical Billing Compliance program connects these operating practices.
The foundational elements
- Screen all employees, contractors, and vendors against the LEIE before engagement and monthly thereafter. Document each check .
- Conduct a HIPAA risk assessment that identifies threats and vulnerabilities to ePHI, assesses potential impact, and implements safeguards. Repeat regularly .
- Execute Business Associate Agreements with every entity that creates, receives, maintains, or transmits PHI .
- Train all workforce members on HIPAA policies at hire and annually. Document attendance and competency .
- Structure referral relationships to comply with the Anti-Kickback Statute. Do not pay for referrals. Do not offer inducements .
The documentation discipline
Medical Billing Compliance requires consistent documentation discipline.
- Require start and stop times on every time-based note
- Tie every intervention to a treatment plan goal
- Update treatment plans on schedule, with signatures
- Conduct concurrent chart audits, not retrospective ones
- Implement standardized templates with required fields
The California layer
Medical Billing Compliance also requires California-specific workflow controls.
- Confirm which system handles authorization for each service type before submitting
- Track Claim training requirements and completion for all clinical staff
- Monitor Blue Shield, Medi-Cal, and county-specific billing policy changes
- Verify dual-eligible patients are enrolled with Medicare for primary payment
How Behavioral Health RCM Services Helps California Providers
Medical Billing Compliance becomes difficult when billing, authorization, documentation, and payer requirements are managed separately. Behavioral Health RCM Services addresses these gaps through a complete RCM workflow built specifically for behavioral health providers.
For California providers, payer and program routing requires particular attention. Behavioral Health RCM Services helps teams verify payer requirements before claims move through the billing process. This is especially important when services involve Medi-Cal managed care, county behavioral health systems, specialty mental health, or DMC-ODS workflows.
This can help with Medical Billing Compliance as compliance checks are done as part of the revenue cycle processes. Providers can uncover workflow issues before they lead to a reimbursement issue or payer denial, instead of waiting for a payer audit or request.
Conclusion
Medical Billing Compliance in behavioral health is not a coding problem. It is an operational discipline that determines whether services get paid and whether the practice survives an audit.
The compliance obligations are specific and enforceable. HIPAA requires risk assessments, BAAs, access controls, and training. The OIG requires exclusion screening and Anti-Kickback compliance. Payers require documentation that proves medical necessity at the level their AI systems can verify. California requires routing to the correct system and completion of CalAIM training.
Medical Billing Compliance depends on every one of these requirements being followed consistently. The enforcement record shows that violations are rarely intentional fraud. They are missing signatures, unverified exclusions, undocumented time, and routing errors. These are administrative failures with substantial consequences.
The practices that treat compliance as a workflow design issue, rather than a job for an after-the-fact clean up, are the ones that ensure revenue and clinician time is saved. Compliance begins with the questions: "Can we document that we did everything we should have in this claim, and will we be able to provide it on request?



