8-Step No Surprises Act Compliance Checklist

A compliant practice must verify protection status, provide required Good Faith Estimates and Advanced EOB readiness where applicable, validate providers and facilities, document consent, apply correct billing and cost-sharing rules, retain audit evidence, and monitor disputes. The financial reason is immediate: by 2024, more than 1.37 million No Surprises Act disputes had closed in a single year, turning compliance failures into recurring denial, write-off, and A/R exposure. HHS and CMS data shows how quickly this moved beyond a policy issue and into daily revenue-cycle operations.
The No Surprises Act took effect on January 1, 2022, and the federal independent dispute resolution process launched on April 15, 2022. For physician owners and practice administrators, the practical question isn't whether the practice has a form. It's whether scheduling, eligibility, credentialing, consent, estimates, claims, collections, and dispute workflows prevent protected encounters from becoming uncollectible balances.
The checklist below is designed for practices deciding whether to repair internal RCM controls or outsource high-risk work. It addresses eligibility, Good Faith Estimates, Advanced EOB readiness, provider and facility validation, patient communications, consent, payer-specific claims, contracts, audit records, training, monitoring, and dispute resolution. Specialty-specific exposure differs. Specialized billing support for high-stakes specialties can be especially relevant for anesthesiology, behavioral health, cardiology, orthopedics, and multi-specialty groups. A focused RCM and compliance audit can help identify whether the larger problem is a notice failure, a coding rule, a directory mismatch, or a downstream denial pattern.
1. Verify Patient Eligibility and Coverage Under No Surprises Act Protections
Eligibility verification is the first revenue-control point because it determines whether the practice can bill the patient beyond in-network cost-sharing. Confirm the patient's insurance status, plan type, network position, and whether the encounter falls under federal or applicable state protections before service delivery. A mistaken assumption at registration can become a prohibited balance bill, a refund, a denial, or a dispute that remains in A/R long after the clinical work is complete.
The No Surprises Act applies differently across emergency services, non-emergency services at participating facilities, air ambulance services, uninsured patients, and self-pay patients. Medicare and Medicaid arrangements also require separate handling. Don't let a generic “active coverage” response serve as the final decision. The practice needs a payer matrix that translates eligibility results into an operational instruction, such as “protected, no balance billing,” “consent workflow required,” or “escalate for plan review.”
Practical rule: Eligibility verification isn't complete until someone records the protection decision and the evidence supporting it.
Build the control into check-in, scheduling, and preauthorization rather than leaving it to the billing team after the claim denies. Use a dedicated EHR flag that staff can't casually override, and record the date, time, payer response, verification method, plan type, and facility relationship. For self-insured plans, maintain a current internal list and route uncertain cases to a designated owner.
A cardiology group, for example, should identify protection status before a referred procedure involving facility, surgeon, anesthesia, and diagnostic components. A behavioral health clinic should distinguish commercial coverage from self-pay status before issuing patient-facing estimates or collecting an out-of-network amount. The No Surprises Act compliance resource for practices can support the policy and workflow design, but the final decision should remain tied to the patient's verified plan and encounter facts.
2. Establish and Maintain an In-Network Provider Directory
Directory accuracy is a contract and cash-collection issue, not merely a patient-information task. If a payer directory lists the wrong location, specialty, group affiliation, credentialing status, or network relationship, the payer may process a clean clinical claim as out of network. That can increase patient responsibility, trigger disputes, delay payment, and create a balance-billing problem the practice could have prevented.
Assign one person ownership of directory data. That owner should maintain a payer-by-payer register covering provider names, National Provider Identifiers, locations, specialties, telephone numbers, group affiliations, credentialing status, effective dates, and submission confirmations. Credentialing, contracting, human resources, scheduling, and billing should all feed changes into the same register. A provider who changes groups or begins working at a new facility shouldn't appear as an administrative surprise to the payer months later.
Use evidence, not assumptions
Search payer portals and public directories using both the practice name and each provider's name. Compare the results with the contracts and the enrollment records used to submit claims. Keep copies of roster submissions, confirmation emails, ticket numbers, and corrected directory entries in the compliance folder.
A gastroenterology practice may be contractually participating while a payer's directory shows the wrong specialty or location. An orthopedic group may add a surgeon to the practice but fail to activate the provider under a major payer before the first patient day. In both scenarios, the resulting out-of-network adjudication can distort denial reporting and make patient collections look stronger than they really are.
Directory maintenance also affects facility-based services. An anesthesiology or cardiology group must verify not only the individual clinician's status, but also the facility relationship and payer configuration for the service location. Review directory data whenever a provider joins, leaves, changes location, changes specialty, or changes group affiliation. Keep a calendar-driven review process, and require billing escalation when a claim's network status conflicts with the directory evidence.
3. Document Informed Consent and Notice Requirements for Out-of-Network Services
Notice and consent can preserve lawful out-of-network billing in limited non-emergency situations, but only when the process is completed correctly and before the service. CMS materials describe required disclosure content that includes network status, potential financial responsibility, and a Good Faith Estimate. For services scheduled more than 72 hours ahead, consent timing generally centers on the 72-hour requirement. If the service is scheduled within 72 hours, the disclosure must be provided at least 3 hours before the service, according to CMS provider responsibilities.
The operational mistake is treating a signature as proof of compliance. The record must show which notice the patient received, the format selected, the date and time delivered, the patient's consent, the services covered, the provider or facility status, and any applicable language or accessibility accommodation. CMS states that the notice must be retained for seven years, so document storage and retrieval are part of the control, not an afterthought.
Make consent a billing gate
For elective services, place consent verification before claim submission and before any balance-billing statement. A missing form should route the account to an exception queue. It shouldn't pass automatically into patient collections.
Use CMS-approved materials or a legally reviewed equivalent. Emergency services require a separate process because notice and consent aren't used to convert protected emergency care into unrestricted out-of-network billing. The same distinction matters for post-stabilization services and for out-of-network clinicians working at participating facilities.
Uninsured and self-pay patients also need a reliable estimate workflow. Practices should use a documented process for Good Faith Estimate requirements and templates and retain the issued estimate, delivery record, revisions, and final charge comparison. A reusable library of compliance documentation templates can help standardize records, but legal and payer review should govern the final forms.
4. Implement Payer-Specific No Surprises Act Billing Codes and Modifiers
A claim can be clinically correct and still fail because the payer's implementation rules don't match the practice's default billing template. Modifier logic, claim indicators, network status, place of service, provider type, and facility participation can affect whether the payer recognizes a protected service, applies in-network cost sharing, or routes the account toward open negotiation and IDR.
Don't assume one modifier works across all payers. CPT 25 may be appropriate in a specific E/M and procedure combination when documentation supports a significant, separately identifiable service, while modifier 59 and the more specific XE may be handled differently by payer policy. The practice owner's financial risk is the same in each case: an unsupported or payer-incompatible modifier can produce a denial, an underpayment, or an avoidable appeal.
Build a payer rulebook
Create a living reference for each major payer. Include claim submission instructions, required indicators, modifier rules, place-of-service treatment, participating facility requirements, open negotiation documentation, QPA disclosures, and escalation contacts. Link each rule to the payer's current provider manual or contract language, and assign an owner to verify updates.
An anesthesiology group should map base-unit, modifier, concurrency, facility, and network variables before claims leave the practice. An orthopedic group should separately evaluate global-period and multiple-procedure rules rather than applying a universal modifier shortcut. A cardiology practice should ensure diagnostic and interventional components are represented consistently with the payer's claim requirements.
Test changes on a controlled batch, compare acceptance and denial reasons, then update the production template. Use out-of-network billing compliance platform guidance as a starting point for system selection, but validate every workflow against the payer's current policy. A modifier is not a compliance strategy by itself. The strategy is a documented connection between the encounter facts, the code, the payer rule, and the evidence retained in the account.
5. Monitor and Audit Patient Cost-Sharing Calculations Under No Surprises Act Rules
Patient responsibility is the most visible compliance control and a direct revenue risk. Protected emergency services generally use in-network cost sharing. Applicable non-emergency services by nonparticipating providers at participating facilities may also fall under No Surprises Act limits. An incorrect charge can create refunds, write-offs, complaints, and regulatory exposure while distorting A/R.
CMS requires providers and facilities to disclose patient protections through three channels, prominent on-site signage, a public website page without a login or paywall, and a one-page notice delivered in person, by email, or by mail according to the patient's preference. CMS disclosure materials reinforces that communication evidence must exist outside the claim record.
Reconcile the estimate, adjudication, and statement
Run a monthly exception report comparing payer adjudication, QPA or recognized-amount information where applicable, the in-network cost-sharing calculation, the original estimate, and the final statement. Flag any account where patient responsibility exceeds the applicable in-network amount or the billing system treats a protected encounter as unrestricted out of network. Track the exception through correction, refund, or documented resolution so the audit trail supports repayment decisions.
Financial counselors and front-desk staff need a consistent script. They should explain whether the encounter is protected, identify the estimate issued, and state that the final amount may change after adjudication without promising a fixed balance. Practices short on front-desk capacity can follow the approach used by clinics using Medical Virtual Assistants to keep estimate and disclosure conversations staffed.
Before sending any statement, verify the encounter's protection flag. If the flag is set, route the account to the refund-risk queue instead of patient collections. Use balance-billing compliance guidance to define statement holds, refund handling, and escalation rules. Connect the exception report to A/R review so overcharges are corrected before they become disputes or aged receivables.
6. Train Clinical and Billing Staff on No Surprises Act Rules and Documentation Requirements
A policy fails when staff can't recognize the event that activates it. Schedulers classify appointment timing. Registration staff capture insurance and facility information. Clinical teams identify emergency and post-stabilization circumstances. Billing staff validate consent, modifiers, cost sharing, and claim routing. Credentialing and contracting staff maintain the network facts that support every downstream decision.
Training should therefore be role-specific. A physician doesn't need the same lesson as a scheduler, and a front-desk employee shouldn't be expected to interpret every IDR rule. The owner needs evidence that each role understands the decisions it controls and knows when to escalate.
Train from actual failure patterns
Create a No Surprises Act playbook with short decision trees for emergency care, non-emergency out-of-network services, self-pay and uninsured estimates, participating facilities, consent timing, protected cost sharing, and dispute intake. Use de-identified denials and refund cases from the practice. Staff retain operational examples better than abstract regulatory summaries.
For anesthesiology, training should focus on facility participation, provider status, consent availability, and claim detail. For mental health, authorization and network classification often need to be tied directly to scheduling. For cardiology and orthopedics, the workflow should connect facility, surgeon, ancillary, and professional components before the patient receives a statement.
Track attendance, completion, and comprehension. A short scenario-based assessment can reveal whether staff know what to do when a patient refuses consent, when a service is booked within 72 hours, or when a remittance code suggests the claim may be ineligible for IDR. Update training promptly when CMS or payer guidance changes, and give the compliance lead authority to stop a workflow that creates recurring patient or payment exposure.
7. Audit and Correct Claims Submitted Without Proper No Surprises Act Compliance
Retrospective auditing turns compliance from a policy exercise into measurable recovery work. Start with denied, underpaid, refunded, and patient-disputed accounts. Then segment by payer, provider, facility, place of service, service category, emergency classification, consent status, and patient responsibility. This reveals whether the practice has a front-end classification problem, a claim-format problem, or a collection problem.
The audit should review more than whether a claim paid. A paid claim can still contain an excessive patient balance or lack the evidence needed to defend the account. Review the notice, consent, Good Faith Estimate, Advanced EOB readiness, eligibility verification, directory evidence, claim details, remittance codes, QPA information, and statement history.
Route accounts by action
Separate findings into operational categories:
- Resubmission candidates: Claims within the payer's correction or appeal window, with a specific coding, documentation, or network error.
- Refund-risk accounts: Patient balances that may exceed applicable cost-sharing limits or lack valid consent.
- IDR candidates: Payment disputes that meet federal eligibility requirements and have supporting documentation.
- Process failures: Repeated errors requiring an EHR rule, payer matrix update, training intervention, or contract review.
CMS data illustrates why dispute readiness matters. In the first half of 2023, providers won 85% of payment determinations across 1.15 million disputes, and awards exceeded the QPA in 87% of determinations, according to the HHS report to Congress. Those results don't justify filing every dispute. They justify preserving complete evidence and screening eligibility before deciding whether to negotiate or enter IDR.
For practices without internal capacity, medical billing audit services can provide an independent review of high-dollar claims, documentation gaps, and denial patterns.
8. No Surprises Act Compliance Program Implementation Roadmap
A workable program starts with sequencing. Don't begin by rewriting every policy. First identify the accounts where a failure can create the largest write-off, refund, denial, or dispute exposure. Then assign owners and install controls at the point where the error occurs.
Immediate controls
Within the initial launch period, freeze unrestricted balance billing for encounters flagged as potentially protected. Add EHR fields for plan type, network status, facility participation, emergency classification, consent status, estimate status, and dispute eligibility. Publish the three required patient-protection disclosures, and create an exception queue for missing documentation.
Thirty-day workflow fixes
Standardize notice, consent, Good Faith Estimate, and statement templates. Build payer-specific claim and modifier rules into the billing reference system. Train scheduling, registration, clinical, credentialing, and billing teams by role. Establish a daily review for upcoming cases where consent or an estimate may be required.
Sixty-day payer and directory review
Reconcile payer contracts, provider rosters, facility affiliations, directories, remittance codes, and claim edits. Confirm that each location and provider is represented correctly. Create escalation rules for claims that the payer identifies as ineligible for IDR, because eligibility screening should happen before staff invest time and filing costs in a dispute.
CMS resources provide a Federal IDR checklist for plans and issuers, including emergency services, non-emergency services by nonparticipating providers at participating facilities, and air ambulance services. The practice should adapt the same discipline to its own dispute intake, documentation, open negotiation, and deadline tracking.
Ninety-day retrospective audit
Review high-dollar claims, denial trends, refund exposure, patient disputes, and aged A/R. Report first-pass clean claim rate, denial rate, protected-encounter write-offs, patient dispute volume, and A/R days to leadership monthly. The roadmap should remain active after implementation because payer rules, directories, remittance codes, and federal guidance change.

8-Point No Surprises Act Compliance Comparison
| Item | Implementation complexity | Resource requirements | Expected outcomes | Ideal use cases | Key advantages |
|---|---|---|---|---|---|
| Verify Patient Eligibility and Coverage Under No Surprises Act Protections | Medium, real-time checks + EHR flags | Front desk/authorization time, EHR integration, payer portal access | Improves first-pass clean claims ~1–3%; reduces balance-bill disputes 60–80% | All specialties; high-volume out‑of‑network referrals (cardiology, orthopedics, anesthesiology) | Prevents illegal balance-billing; enables accurate financial counseling; creates audit trail |
| Establish and Maintain an In‑Network Provider Directory | High, ongoing multi‑payer maintenance | Dedicated admin/credentialing staff, quarterly audits, manual payer submissions | First-pass clean claims +2–4%; reduces out‑of‑network downgrades 70–90% | Multi‑location groups, practices with frequent provider changes | Ensures in‑network processing; reduces patient confusion and lost revenue |
| Document Informed Consent and Notice Requirements for Out‑of‑Network Services | Medium, workflow and pre‑service discipline | Standardized consent forms (CMS1694), staff training, EHR storage | Collect 60–90% of OON balances vs 10–30% without documentation | Anesthesiology, surgery, interventional specialties, facility‑based care | Legal defensibility for balance‑billing; reduces disputes and claim downgrades |
| Implement Payer‑Specific No Surprises Act Billing Codes and Modifiers | High, payer‑specific rules and frequent updates | Experienced billers, payer modifier lookup, billing system customization | First-pass clean claims +2–5%; reimbursement +1–3% (varies by practice) | Multi‑procedure specialties and out‑of‑network facility services | Reduces denials/underpayments; improves audit defense and cash flow |
| Monitor and Audit Patient Cost‑Sharing Calculations Under No Surprises Act Rules | High, complex calculations, payer data needs | Billing software enhancements, payer recognized‑amount data, audit staff, refund process | Improves collections 5–15%; eliminates many refund liabilities | Emergency medicine, anesthesiology, facility‑based services | Prevents overcharges; reduces refunds, regulatory complaints, and collections friction |
| Train Clinical and Billing Staff on No Surprises Act Rules and Documentation Requirements | Medium, ongoing program with refreshers | Training materials or vendor, staff time, tracking and testing | First-pass clean claims +3–8%; denials down 20–40% | All specialties; especially multi‑specialty practices and high turnover | Reduces compliance errors; documents good‑faith efforts for audits; empowers staff |
| Audit and Correct Claims Submitted Without Proper No Surprises Act Compliance | High, retrospective, resource‑intensive | Audit expertise (internal or external), appeals capacity, staff time | Can recover $50k–$500k+ depending on size and historical gaps | Practices with historical OON or complex billing (anesthesia, cardiology) | Recovers lost revenue; identifies systemic root causes; improves future compliance |
| No Surprises Act Compliance Program, Implementation Roadmap | Medium–High, coordinates multiple initiatives | Leadership sponsor, assigned roles, EHR/third‑party tools, phased project plan | Combined ROI: improved clean claims, fewer denials/refunds; tens–hundreds of thousands for midsize practices | Practices seeking comprehensive, organized compliance across functions | Single actionable plan with KPIs; combines preventive and corrective measures and clarifies responsibilities |
Turn the Checklist Into a Revenue Control System
The No Surprises Act became effective on January 1, 2022, and federal IDR launched on April 15, 2022. By the first half of 2023, CMS data showed 83,849 disputes had already been decided. By 2024, more than 1.37 million disputes closed in one year, which means a practice that treats compliance as a static notice packet is operating inside a rapidly expanding payment-dispute environment. Federal data supports the owner-level conclusion: operational controls matter because claim volume and dispute volume can grow faster than manual review capacity.
Start with high-dollar claims and denial patterns. Pull protected emergency claims, out-of-network claims at participating facilities, self-pay encounters, refunded accounts, and patient disputes. Identify the failure point, then assign one accountable owner. Eligibility belongs in registration and scheduling. Directory accuracy belongs with a named credentialing or contracting owner. Consent and estimates belong in the pre-service workflow. Cost sharing, claim rules, and dispute evidence belong in RCM with compliance oversight.
The financial metrics should be visible every month:
- First-pass clean claim rate: Shows whether payer-specific claim rules and documentation are working before rework begins.
- Denial rate: Separates network, modifier, consent, eligibility, and cost-sharing failures instead of hiding them in one total.
- Refund exposure: Identifies protected accounts that may require correction before patient complaints escalate.
- Patient dispute volume: Signals whether statements, estimates, and cost-sharing decisions are creating avoidable friction.
- A/R days: Shows whether compliance failures are slowing payment, increasing manual follow-up, or creating unresolved IDR inventory.
A practical implementation timeline is straightforward. Install immediate flags, statement holds, public disclosures, and escalation ownership first. Use the next 30 days for workflow templates and role-based training, the next 60 days for payer, directory, and facility reconciliation, and 90 days for a retrospective claim audit and leadership review. Those timeframes are implementation targets, not regulatory deadlines, so the practice should adjust them to staffing, volume, and legal guidance.
Historical IDR outcomes also affect contract strategy. Providers won 85% of payment determinations in the first half of 2023, and awards exceeded the QPA in 87% of determinations, according to CMS and HHS reporting. A practice shouldn't interpret that as permission to submit weak disputes. It should preserve the clinical record, contract terms, network evidence, estimate, consent, claim, remittance, and negotiation history so a qualified dispute can be evaluated efficiently.
What should a small practice fix first?
Fix the controls that stop an incorrect patient bill from being created. Start with eligibility and protection flags, consent and Good Faith Estimate workflows, a statement hold for protected encounters, and a clear escalation owner. A small practice usually gains more from reliable exception handling than from purchasing a complex platform before understanding its denial and refund patterns.
When do we need a Good Faith Estimate or Advanced EOB workflow?
Use a Good Faith Estimate workflow for uninsured and self-pay patients when applicable, and make sure it includes the expected services and related components your practice can reasonably identify. Advanced EOB readiness requires coordination with payer data, patient estimates, provider and facility information, and expected cost sharing. The exact operational scope can depend on current federal implementation and guidance, so owners should have counsel or a qualified compliance resource validate the workflow.
Can we outsource No Surprises Act compliance with RCM?
You can outsource much of the operational work, including eligibility review, claim edits, denial management, documentation audits, directory follow-up, and dispute preparation. Keep executive accountability and policy approval inside the practice. The vendor should work inside the existing EHR where possible, document every decision, and report compliance-related revenue metrics alongside ordinary RCM results.
How should we measure whether the program is working?
Track first-pass clean claim rate, denial rate by root cause, protected-encounter write-offs, refund exposure, patient dispute volume, open negotiation and IDR inventory, and A/R days. Review the same measures monthly by payer, provider, facility, and specialty. If the practice can't connect a compliance failure to a financial result, it won't know whether the workflow is protecting revenue or merely generating paperwork.
Happy Billing provides full-cycle RCM, denial management, documentation audits, credentialing support, and A/R recovery for practices managing No Surprises Act exposure. Visit Happy Billing to discuss a workflow that connects eligibility, consent, payer-specific claims, audit evidence, and dispute readiness to measurable revenue-cycle performance.