• Subscribe
  • Log In
  • Sign up for email updates
  • Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer

The Texas Lawbook

Free Speech, Due Process and Trial by Jury

  • Appellate
  • Bankruptcy
  • Trials & Litigation
    • Business Litigation of the Year
    • Employment
    • Energy/Environmental
    • IP/Patent
    • Mass/Toxic Torts
    • Texas Business Court
  • Corporate Deal Tracker
  • GCs/Corp. Legal Depts.
  • Firm Management
  • White-Collar/Regulatory
  • Pro Bono/Public Service/D&I

What Buyers Are Really Underwriting in Texas Healthcare Deals: Regulatory History

October 2, 2026 Megan Neel

In June, the U.S. Department of Justice announced a $56.5 million False Claims Act resolution involving Matrix Medical Network, HealthFair and HealthFair’s founder. Matrix acquired HealthFair in 2018 and shut down its operations by 2020. The conduct alleged against HealthFair dated to 2015 through 2017, and the allegations were not resolved until 2026, years after the acquired business had ceased to exist.

That chronology captures what makes healthcare due diligence different. In most industries, diligence is designed to determine a business’s value. In healthcare, buyers must answer a second, equally important question: What regulatory history are they acquiring along with the business?

The question is getting harder to defer. The same month, DOJ announced its 2026 National Health Care Fraud Takedown, charging 455 defendants, including 90 physicians and other licensed professionals, in alleged schemes involving more than $6.5 billion in false claims. Government scrutiny of healthcare businesses is substantial and increasingly sophisticated, and it does not reset when ownership changes.

For general counsel and deal lawyers advising private equity sponsors, strategic acquirers, physician groups, management services organizations (MSOs) and hospitals, that shift changes what diligence is for. It is no longer enough to confirm that a target’s financials hold up and its contracts are in place. Years of referral relationships, compensation arrangements, billing practices, internal compliance findings and privacy safeguards become the buyer’s problem at closing, and they drive purchase price, indemnities, escrows, whether representations and warranties insurance will actually respond, and the buyer’s eventual exit.

The central question is not simply whether the target is a good business today. It is whether the organization has been structured, governed and operated in a way that will withstand scrutiny tomorrow.

You Are Buying the Regulatory Past

Healthcare regulatory risk does not necessarily disappear when ownership changes.

A transaction can transfer an operating business, but it does not erase the history behind physician relationships, improper arrangements, data security, coding practices or internal compliance findings. Buyers, therefore, need to understand not only what a target is doing now, but what happened before they arrived.

The Matrix and HealthFair resolution illustrates why. The allegations involved invalid diagnosis codes submitted in connection with the Medicare Advantage program, and HealthFair’s alleged conduct predated Matrix’s ownership entirely.

The resolution should not be read as establishing that an acquirer automatically becomes liable for everything an acquired company did before closing. The settlements resolved separate allegations, and DOJ expressly stated that there had been no determination of liability.

The chronology nonetheless provides an important lesson for buyers: Historical conduct associated with an acquired business can remain relevant long after the transaction and even after the acquired operation itself has ceased to exist.

This is why healthcare diligence needs to reconstruct the target’s regulatory past. Buyers should understand prior contractual arrangements, government audits, complaints, internal investigations, repayment issues, whistleblower allegations, billing and coding methodologies and changes in compliance practices. A clean current-state snapshot may not reveal the exposure created years earlier.

For investors, this also has implications beyond the initial acquisition. A compliance issue missed in today’s buy-side diligence can become tomorrow’s disclosure problem, indemnification dispute, valuation adjustment or obstacle to an exit.

Regulatory diligence, therefore, is not separate from enterprise value. It is part of the underwriting.

Do the Economics Match the Paperwork?

Some of the most important healthcare diligence occurs not simply in determining whether a compliant written agreement exists, but in confirming that the parties are actually operating in accordance with the economics and compensation methodology set out in that agreement. This is particularly important in Texas physician practice and MSO transactions, where investors frequently encounter management agreements, physician compensation arrangements, medical director agreements, space and equipment leases, ownership interests and referral relationships.

Under the Stark law and the Anti-Kickback Statute — the two federal laws that police financial relationships between healthcare providers and the people who refer patients to them — form alone is not enough. Buyers need to understand whether the economics of an arrangement are consistent with the written agreement. The agreement itself must clearly define the services being provided and the methodology used to determine compensation, and the parties’ actual conduct must match those terms. For MSO arrangements relying on an applicable Anti-Kickback Statute safe harbor, for example, the agreement generally must be in writing and signed by the parties, specify the services to be provided and establish the methodology for determining compensation in advance. That compensation methodology must be consistent with fair market value in an arm’s-length transaction and may not be determined in a manner that takes into account the volume or value of referrals or other business generated between the parties.

For buyers, that means diligence should go beyond reviewing the signed agreement. It should test whether payments were actually calculated and made in the manner the agreement requires. A fixed or otherwise compliant compensation methodology on paper will not resolve the concern if actual payments function differently in practice or are tied, directly or indirectly, to referral volume or value.

Recent enforcement involving laboratory referrals makes that point particularly relevant in Texas.

In June, DOJ announced more than $2 million in FCA settlements involving a former laboratory CEO, a former laboratory sales executive, a physician and several marketers, including several individuals in Texas, over alleged kickbacks for laboratory referrals. DOJ said it has recovered more than $61 million since 2019 in civil FCA settlements involving kickbacks allegedly disguised as MSO investment distributions, including recoveries from more than 50 physicians.

For a buyer evaluating an MSO or physician relationship, the lesson is not that the economics can be left vague and evaluated later. The opposite is true. The compensation methodology should be clearly set forth in the agreement, and diligence should confirm that the parties’ actual financial relationship has followed that methodology without being influenced by the volume or value of referrals.

The mechanics of an arrangement should matter to buyers evaluating MSO-backed physician relationships. Calling a payment an “investment distribution” or a “management fee” does not answer the regulatory question; there must be a contract in place that justifies those payments. The question is not simply whether a structure is common in the market. It is whether the specific structure being acquired is based on a compliant contract and whether the payment actually made is defensible.

Diligence should examine whether the operational reality is consistent with the contracts.

A Lease Can Be a Regulatory Issue

Even ordinary commercial arrangements can carry regulatory consequences in the healthcare industry.

In April, Trinity Hospital agreed to pay $1.7 million to resolve allegations involving financial relationships with two referring physicians. Trinity identified the arrangements through an internal compliance review and independent investigation and determined there were improper financial contributions to referring physicians in the form of rental agreements for office space. Trinity took remedial action and disclosed the matter to the government, which alleged the arrangements exceeded fair market value. The DOJ acknowledged that Trinity promptly took remedial action and credited the hospital’s cooperation in resolving the matter.

For buyers, Trinity illustrates both sides of the diligence equation.

First, confirming that a lease has been executed is not sufficient. A buyer may also need to determine whether the rent reflects fair market value, whether the arrangement has changed over time, and whether the relationship involves physicians who are in a position to refer the kinds of services the Stark law covers.

Second, the Trinity case shows the value of a functioning compliance infrastructure. Trinity’s internal processes identified a potential problem, leading to remediation and disclosure.

When diligence identifies a historical compliance issue, the buyer should also determine how the target responded to it. A company that recognized, investigated and corrected a problem presents a different risk profile than an organization whose management received warnings and did nothing.

Ask What Management Knew and What It Did

Buyers routinely ask whether a target has undergone contract audits, policy compliance audits, coding reviews or outside assessments. A “yes” answer should begin the inquiry, not end it. The next question should be what was done after the audit.

In May, psychiatric hospital operator Oglethorpe Inc. and three executives agreed to pay $32 million to resolve FCA allegations that they knowingly failed to return Medicare overpayments related to patients allegedly ineligible for inpatient psychiatric care. According to the DOJ, the company’s own consultants had identified the overpayments.

Oglethorpe had previously entered into a corporate integrity agreement with the Department of Health and Human Services Office of Inspector General. In connection with the 2026 resolution, Oglethorpe and the executives also agreed to a 10-year exclusion from Medicare, Medicaid and other federal healthcare programs beginning in July. The claims were allegations, and no determination of liability was made.

For an acquirer, the important diligence lesson is straightforward: Do not merely ask whether someone reviewed the target’s compliance.

Ask what they found and how it was corrected.

Buyers should request material audit reports, consultant findings, coding reviews, overpayment analyses, internal investigation reports and compliance committee materials. They should determine who received those findings, whether they were escalated to senior management or the board, whether repayments or corrective action was recommended, and what management actually did.

An unresolved problem is important. Evidence that management knew about a problem and failed to address it can be more significant.

Inquiries about corrective action can also reveal something broader about the target’s governance. Compliance infrastructure is not measured solely by whether a company has policies, a hotline or annual training. It is measured by whether the organization responds when those systems identify a problem.

Cybersecurity Is Also an M&A Diligence Issue

The same principle applies to privacy and cybersecurity.

Buyers sometimes treat HIPAA diligence as an information technology workstream that can be addressed after the transaction. Recent enforcement by the HHS Office for Civil Rights (OCR) demonstrates why that approach can be risky.

In March, the OCR announced a settlement with healthcare software company MMG Fusion following an investigation into a breach affecting approximately 15 million individuals. The OCR identified potential violations, including a failure to conduct an accurate and thorough risk analysis. The settlement marked the OCR’s 12th enforcement action under its Risk Analysis Initiative.

Then, in July, the OCR announced its 21st ransomware enforcement action, involving OSF Healthcare System. The OCR’s investigation followed a 2021 ransomware attack affecting the protected health information of more than 53,000 individuals. Among the potential violations identified by the OCR was a failure to conduct an accurate and thorough HIPAA risk analysis. OSF agreed to pay $552,250 and implement a corrective action plan.

The transactional implication is significant.

A buyer acquiring a healthcare organization also acquires its information environment. Due diligence should therefore evaluate not simply whether the target reports prior breaches, but whether it knows where protected health information resides, has conducted appropriate risk analyses, has addressed identified vulnerabilities and has an effective incident response and breach-notification process.

Questions about privacy compliance also belong in integration planning. Waiting until closing to understand the target’s privacy and security infrastructure can leave the buyer exposed during the period when systems, vendors, employees and data environments are being combined.

Structure the Deal Around What Diligence Finds

Not every regulatory issue identified during diligence requires a buyer to walk away, but material issues may affect the transaction.

Some problems can be remedied before closing. Others may require a voluntary disclosure, repayment, restructuring of a physician relationship, modification of a management agreement or implementation of additional compliance controls.

Still others may need to be addressed economically through purchase-price adjustments, specific indemnities, escrows, holdbacks or other risk-allocation mechanisms.

Representations and warranties insurance may also play a role, but buyers should understand the scope of healthcare-related exclusions and whether a known compliance issue falls outside coverage.

The objective is not to eliminate every conceivable regulatory risk; that is rarely possible. The objective is to understand what risk the buyer is actually assuming and make a deliberate decision about how to allocate, price or remediate it.

Own Day One

Closing does not end regulatory diligence. It changes who owns the problem.

The first days following a healthcare acquisition should include a deliberate compliance integration process addressing governance, physician relationships, contractual arrangements, HIPAA safeguards, reporting mechanisms, open audits, billing and coding controls, identified overpayments and unresolved internal findings.

Planning for future compliance should begin before closing.

A buyer that identifies a questionable lease during diligence should know how it will be corrected. A buyer that discovers weaknesses in a HIPAA risk analysis should have a remediation plan. A buyer that learns about improper payment arrangements should request immediate corrective action prior to closing.

The objective is to avoid discovering after closing that everyone knew about the issue, but no one owned the response.

A Different Healthcare Diligence Playbook

Recent enforcement suggests that sophisticated healthcare buyers should organize diligence around four questions:

  • What regulatory history are we acquiring? Review contractual or “handshake” arrangements with internal and external parties, audits, investigations, repayment issues, complaints and internal findings rather than relying solely on verbal representations.
  • Do the economics match the paperwork? Examine the financial reality behind MSO structures, physician compensation, management fees, leases, ownership interests and referral relationships.
  • What did management know, and what did they do? Determine not only whether compliance reviews occurred, but what they found, who received the findings and whether appropriate remediation followed.
  • What has to be fixed on Day One? Identify governance, contracts, privacy, billing, reporting and operational weaknesses that will become the buyer’s responsibility immediately after closing.

Regulatory concerns affect far more than legal risk. They can influence valuation, transaction timing, deal structure, integration costs and ultimately the buyer’s ability to exit the investment.

In healthcare transactions, the most expensive regulatory problem is often not the one everyone can see. It is the historical issue that appears years after the acquisition and raises a question the buyer wishes it had asked before closing.

The strongest acquirers are not necessarily those willing to pay the highest price. They are the ones that understand what they are actually buying, including the regulatory past.

Megan Neel is a Board-Certified Health Law attorney in FBFK Law’s Houston office with more than two decades of experience counseling healthcare organizations on complex operational and regulatory matters. She has worked with direct primary care practices, counseling groups, medical spas, multi-site physician practices, national telehealth providers and integrated healthcare enterprises on transactions, regulatory compliance, strategic contractual relationships, ownership structures and operational risk management. She can be reached at mneel@fbfk.law.

©2026 The Texas Lawbook.

Content of The Texas Lawbook is controlled and protected by specific licensing agreements with our subscribers and under federal copyright laws. Any distribution of this content without the consent of The Texas Lawbook is prohibited.

If you see any inaccuracy in any article in The Texas Lawbook, please contact us. Our goal is content that is 100% true and accurate. Thank you.

Primary Sidebar

Recent Stories

  • What Buyers Are Really Underwriting in Texas Healthcare Deals: Regulatory History
  • P.S. — Law Firms, Corporate Counsel Link Arms to Help Families Plan Ahead, A&M Law Professor Wins Back-to-Back Honors
  • Trump to Nominate Phelps Dunbar Partner to Succeed Fifth Circuit Judge Southwick
  • Dallas Attorneys Win Dismissal of Cryptocurrency Memecoin RICO Suit
  • Texas Bankruptcy Experts Give Thumbs Up to Increasing Small Business Debt Limits

Footer

Who We Are

  • About Us
  • Our Team
  • Contact Us
  • Submit a News Tip

Stay Connected

  • Sign up for email updates
  • Article Submission Guidelines
  • Premium Subscriber Editorial Calendar

Our Partners

  • The Dallas Morning News
The Texas Lawbook logo

1409 Botham Jean Blvd.
Unit 811
Dallas, TX 75215

214.232.6783

© Copyright 2026 The Texas Lawbook
The content on this website is protected under federal Copyright laws. Any use without the consent of The Texas Lawbook is prohibited.