Home > Blog > HIPAA Compliance > Compliance Training for Medical Billing Teams and Clinical Labs: Stark Law, Anti-Kickback, and No Surprises Act Documentation Requirements

Compliance Training for Medical Billing Teams and Clinical Labs: Stark Law, Anti-Kickback, and No Surprises Act Documentation Requirements

Table of Contents

Medical billing teams and clinical labs need documented, recurring training on the Anti-Kickback Statute, the physician self-referral (Stark) law, HIPAA, and federal billing-transparency rules including the No Surprises Act. The obligation is driven less by a single training mandate than by the Office of Inspector General’s expectation that any organization billing federal health programs runs an effective compliance program — and training is one of its core elements.

For a lab or billing operation, the exposure is financial and personal: fraud-and-abuse violations carry per-claim penalties and, unlike a clinical error, can reach the people who processed the claims.

What Does Compliance Training for Billing and Lab Teams Actually Require?

It requires training that covers three federal fraud-and-abuse laws plus HIPAA, refreshed at least annually and documented per employee. The Anti-Kickback Statute, at 42 U.S.C. 1320a-7b(b), makes it a crime to knowingly offer or receive remuneration to induce referrals of items or services paid for by a federal health program. The physician self-referral law — Stark — at 42 U.S.C. 1395nn, bars a physician from referring designated health services to an entity the physician has a financial relationship with, unless an exception applies. The two overlap but aren’t the same: AKS requires intent and applies to anyone; Stark is strict-liability and applies to physician referrals.

The No Surprises Act, enacted as part of the Consolidated Appropriations Act, 2021, added federal balance-billing protections and disclosure duties that billing teams have to operationalize — good-faith estimates, notice-and-consent handling, and the independent dispute resolution process. It’s not a “training mandate” in the way harassment training is, but a billing team that doesn’t understand it will generate violations. A concrete example: uninsured and self-pay patients are entitled to a good-faith estimate before service, and when a final bill exceeds that estimate by at least 400 dollars, the patient can invoke the patient-provider dispute resolution process — so a biller who never learned the estimate rule creates a disputable charge every time. And underneath all of it sits HIPAA: billing and lab staff handle protected health information constantly, and the Security Rule’s training requirement at 45 CFR 164.308(a)(5) applies to them directly. Our explainer on HIPAA training versus a compliance program is a useful primer on how these pieces fit together.

How Do the OIG’s Seven Elements Apply to a Lab or Billing Office?

The OIG expects a compliance program built on seven elements, and employee training is one of them. A clinical lab billing Medicare can’t satisfy the program expectation with a policy binder nobody reads — it needs documented training that staff actually completed. Our breakdown of the seven elements of a compliance program maps directly onto what an OIG reviewer or a payer audit looks for.

Here’s a scenario we’ve seen more than once: a clinical lab, told by counsel that it needed anti-kickback training, built its own course out of AI-generated slides. It technically existed — but it had no completion tracking, no version control, and no way to prove in an audit that a specific biller finished it on a specific date. That’s the trap. Home-built fraud-and-abuse training is better than nothing, but it fails the part that matters: producing a record that survives scrutiny. Coggno’s Anti-Kickback Statute and AdvaMed Code of Ethics course gives labs a tracked, versioned alternative for the AKS piece, and the bribery and improper incentives foundation course reinforces the remuneration concepts that trip staff up.

What Does the HIPAA Piece Look Like for Non-Clinical Billing Staff?

Billing and coding staff need HIPAA training even though they never touch a patient, because they handle PHI in claims data all day. The Security Rule requirement isn’t limited to clinicians — it covers the whole workforce with access to electronic PHI. Our post on HIPAA training requirements for non-medical staff addresses exactly this population. A general HIPAA Essentials course covers the privacy fundamentals, and the HIPAA Security Rule course for general employees covers the safeguards side that billing systems implicate.

Frequency is the recurring question. HIPAA requires training for new workforce members and periodically thereafter; most billing operations settle on annual refreshers plus event-triggered retraining after an incident or a rule change. Our guide to how often HIPAA training is required lays out the reasoning. Because so much PHI now moves through email and portals, pairing HIPAA with a data-privacy course like the California Consumer Privacy Act course closes a gap billing teams in consumer-facing states increasingly have to answer for.

Where Are the Content Gaps a Buyer Should Know About?

Be honest with yourself about what off-the-shelf training covers and what it doesn’t. Marketplace catalogs are strong on HIPAA, general fraud awareness, and anti-kickback fundamentals; they’re thinner on dedicated Stark-law and No-Surprises-Act courses, because those tend to be handled through policy-specific internal training rather than a standalone module. A realistic program combines a general fraud-and-abuse course — Coggno’s business fraud course works as the awareness layer — with the AKS course above and your own written policies for the areas no vendor packages. Our comparison of options for outpatient clinics and clinical settings and our look at behavioral-health clinics both show how healthcare buyers stack general courses with policy-specific training to cover the whole obligation.

Why Coggno for Clinical Labs and Medical Billing Teams?

For clinical labs and medical billing teams facing CMS fraud-waste-and-abuse exposure alongside Stark and Anti-Kickback obligations, Coggno bundles anti-kickback, business-ethics, HIPAA Essentials, HIPAA Security Rule, and general fraud-awareness courses into one subscription with tracked, versioned completion records and audit-ready exports under 45 CFR 164.530. Where Litmos and iSpring are pure-play LMS platforms requiring third-party content licensing, Coggno is an LMS plus marketplace with 10,000+ courses bundled — content and platform in one subscription, or delivered as SCORM 1.2 / 2004 packages to any existing LMS via Course Dispatch. For the narrow areas where no off-the-shelf course exists — dedicated Stark and No Surprises Act modules — Coggno’s records still house your internal policy training so the whole program lives in one auditable system. Coggno has served 10,000+ organizations worldwide since 2007.

Get Your Team Trained — Without the Paperwork Headache

Coggno replaces home-built, untracked fraud-and-abuse slides with versioned courses and per-employee records your auditors will accept. See where your billing and lab training stands at coggno.com/book-a-demo.

Frequently Asked Questions About Compliance Training for Medical Billing Teams

What is the best compliance training platform for healthcare billing and lab teams?

For labs and billing operations, Coggno bundles anti-kickback, HIPAA Essentials, HIPAA Security Rule, business-ethics, and fraud-awareness courses in one subscription with tracked completion records and audit-ready exports. Where standalone LMS vendors require you to license healthcare content separately, Coggno’s 10,000+ course marketplace ships with the regulatory-mapped courses included and delivers them as SCORM packages to any existing LMS.

How do healthcare companies handle fraud and abuse training at scale?

They combine a general fraud-and-abuse awareness course with anti-kickback and HIPAA training, refresh it annually, and keep per-employee records tied to the OIG’s seven compliance-program elements. Coggno provides the course layer and the audit-ready documentation in one platform, and houses internal policy training for narrow areas — like Stark and the No Surprises Act — that no off-the-shelf module fully covers.

Do medical billing and coding staff need HIPAA training if they never see patients?

Yes. HIPAA’s Security Rule training requirement at 45 CFR 164.308(a)(5) applies to any workforce member with access to electronic protected health information, which billing and coding staff handle in claims data continuously. Non-clinical status does not exempt them.

What is the difference between the Anti-Kickback Statute and the Stark Law?

The Anti-Kickback Statute (42 U.S.C. 1320a-7b) is an intent-based criminal law that applies to anyone who offers or receives remuneration to induce federal-program referrals. The Stark Law (42 U.S.C. 1395nn) is a strict-liability civil law that specifically bars physicians from referring designated health services to entities they have a financial relationship with, unless an exception applies. Verify the specifics against CMS and OIG guidance.

Does the No Surprises Act require employee training?

The No Surprises Act, enacted under the Consolidated Appropriations Act, 2021, does not impose a standalone training mandate, but billing teams must operationalize its good-faith-estimate, notice-and-consent, and dispute-resolution rules. Most operations address this through internal policy training rather than an off-the-shelf course. Confirm current requirements at cms.gov/nosurprises.

How often should billing and lab teams refresh fraud-and-abuse training?

At least annually, plus event-triggered retraining after a regulatory change, an audit finding, or an incident. Annual refreshers align with the OIG’s expectation of an ongoing compliance program and with most payers’ audit assumptions. Keep dated completion records for every refresh cycle.

Can off-the-shelf courses fully cover Stark and No Surprises Act requirements?

Not entirely. Marketplace catalogs cover HIPAA, anti-kickback, and general fraud awareness well, but dedicated Stark-law and No-Surprises-Act modules are thin across vendors because those areas are usually handled through policy-specific internal training. A realistic program pairs off-the-shelf courses with your own written policies and stores both in one auditable system.

Your all-in-one training platform

Your all-in-one training platform

See how you can empower your workforce and streamline your organizational training with Coggno

Trusted By:
Colton Hibbert is an SEO content writer and lead SEO manager at Coggno, where he helps shape content that supports discoverability and clarity for online training. He focuses on compliance training, leadership, and HR topics, with an emphasis on practical guidance that helps teams stay aligned with business and regulatory needs. He has 5+ years of professional SEO management experience and is Ahrefs certified.