America's Essential Hospitals

09/18/2026 | Press release | Distributed by Public on 09/18/2026 07:01

Navigating Off-Campus HOPD Attestation and NPI Requirements

The Consolidated Appropriations Act, 2026 established new requirements for off-campus hospital outpatient departments (HOPDs). Beginning Jan. 1, 2028, hospitals must obtain a separate National Provider Identifier (NPI) for each applicable department, submit provider-based compliance attestations, and comply with ongoing reattestation requirements. Failure to comply could jeopardize Medicare reimbursement and increase risk of payment recovery actions from CMS.

For 340B hospitals, the stakes are higher. Drugs dispensed in a department that cannot substantiate its provider-based status are ineligible for the program.

In its 2027 Outpatient Prospective Payment System (OPPS) proposed rule, the Centers for Medicare & Medicaid Services (CMS) issued preliminary regulations implementing these requirements. Hospital leaders should consider the following steps to prepare for the 2028 start date.

Step 1: Establish a Cross-Functional Provider-Based Compliance Team

The new requirements touch virtually every aspect of hospital operations for off-campus HOPDs. Hospitals should establish a formal, cross-functional steering committee immediately to oversee the preparation process.

The team should include representatives from:

  • Compliance: To lead provider-based reviews, coordinate documentation readiness, monitor regulatory developments, manage gap assessments, and oversee audit preparedness.
  • Patient Financial Services/Billing: To evaluate effects on claim submission, place-of-service requirements, charge routing, and payor-specific billing implications.
  • Reimbursement and Revenue Integrity: To assess OPPS payment implications, provider-based status requirements, Medicare enrollment issues, and reimbursement risks.
  • Clinical Operations and Practice Management: To validate clinical integration, physician credentialing, reporting relationships, referral patterns, signage, and patient-facing operational requirements.
  • Finance: To verify financial integration requirements, including trial balance reporting, cost reporting considerations, and departmental ownership and control structures.
  • Provider Enrollment: To manage new NPI acquisition; Provider Enrollment, Chain, and Ownership System (PECOS) updates; and attestation submissions.
  • Information Technology (IT): To evaluate how department-level NPIs will affect registration, scheduling, billing, revenue cycle, reporting, and other enterprise systems.
  • Pharmacy and 340B Program Leadership (for Covered Entities): To assess implications for 340B child site eligibility and ensure provider-based documentation supports ongoing program participation.

CMS is moving toward a standardized national attestation form and process. Hospitals that assign clear ownership and governance now may be better positioned to demonstrate compliance when attestations become mandatory.

Step 2: Identify All Affected HOPDs

The requirements apply to off-campus HOPDs paid under OPPS, excluding critical access hospitals, Indian Health Service facilities, Rural Health Clinics, and federally qualified health centers. Hospitals should develop a comprehensive inventory of all provider-based departments and validate which locations are subject to the requirements.

The inventory should include:

  • Department name
  • Physical address
  • Current CMS enrollment status
  • Existing billing NPI(s)
  • Distance from the main campus
  • State licensure status
  • 340B participation status
  • Operational ownership structure

Beginning with a good inventory and gap assessment is essential, as correcting deficiencies often takes significant time.

Step 3: Develop an NPI Implementation Strategy

CMS will require each applicable department to obtain a separate NPI and update PECOS enrollment records before submitting an attestation. This will likely affect:

  • Patient accounting systems
  • Charge master configurations
  • Revenue cycle workflows
  • Claims editing systems
  • Scheduling applications
  • Practice management systems
  • Data warehouses
  • 340B split-billing software
  • Managed care contracting
  • Revenue integrity

Developing an IT plan is critical, because the new NPIs will affect multiple systems throughout the organization.

Hospitals should also evaluate how department-level NPIs affect managed care contracting, provider directories, authorizations, network participation, reimbursement methodologies, and payor credentialing requirements.

Step 4: Conduct a Provider-Based Compliance Gap Assessment

CMS is expected to increase oversight for compliance with provider-based department requirements through a multitiered process that includes automated reviews, targeted reviews, audits, and extended compliance investigations. Hospitals should evaluate compliance and compile supporting documentation across the following categories.

Public Awareness

Patients must clearly understand they are receiving services from the hospital. Hospitals should review:

  • Exterior signage
  • Interior wayfinding signage
  • Directories
  • Appointment cards
  • Business cards
  • Websites
  • Marketing materials
  • Telephone answering protocols

All materials must reflect the hospital's Medicare-recognized provider name, not merely the health system brand.

Clinical Integration

Hospitals should confirm:

  • Practitioners have appropriate hospital privileges.
  • Hospital leadership exercises oversight of clinic operations.
  • Providers report through hospital governance structures.
  • Patients have access to the full range of hospital services.

Potential supporting documentation includes medical staff bylaws, practitioner privilege lists, organizational charts, referral reports, patient care policies, nondiscrimination policies, and accreditation records.

Financial Integration

Hospitals should verify that:

  • Department revenues and expenses appear directly on the hospital trial balance
  • A separate general ledger is not maintained
  • Financial activity is embedded within the hospital's accounting structure

Supporting documentation may include trial balances and charts of accounts demonstrating full financial integration. Monthly journal entries that move expenses and revenue from the clinic general ledger to the hospital general ledger are a common compliance red flag.

Ownership and Control

The department must be wholly owned and controlled by the hospital. Hospitals should confirm:

  • The hospital maintains 100% ownership.
  • Administrative authority remains with the hospital.
  • Purchasing and contracting authority ultimately resides with hospital leadership.

Hospitals should evaluate any management agreements, joint operating arrangements, or other complex operating structures for consistency with provider-based requirements.

Supporting documentation may include governance documents, narratives, bylaws, current organizational charts, and purchasing authority records.

Administrative Integration

CMS expects off-campus HOPDs to operate as hospital departments rather than independent clinics.

Hospitals should evaluate:

  • Reporting structures
  • Management oversight
  • Governance reporting
  • Administrative policies
  • Management agreements

Hospitals must also demonstrate that the documented reporting relationships from the clinic to the hospital executives exist in practice.

Step 5: Validate Location and Licensure Requirements

Hospitals should review each department's location relative to the main campus to ensure it meets the 35-mile requirement or there is readily available documentation supporting an exception.

Hospitals also should verify licensure requirements. Some states permit departments to operate under the hospital's existing license, while others require separate licensing or additional approvals.

Step 6: Verify Revenue Cycle Compliance

Revenue cycle teams should conduct targeted reviews to validate:

  • Correct place-of-service coding (POS 19)
  • Claim submission practices
  • Beneficiary financial notification processes
  • Emergency Medical Treatment and Labor Act-related procedures where applicable

It is crucial that hospitals maintain documentation supporting beneficiary financial notifications.

Step 7: Assemble an Audit-Ready Documentation Repository

Documentation readiness is crucial to successfully navigate future CMS reviews of provider-based status. CMS is expected to employ a multilevel verification structure that may include:

  1. Automated review
  2. Targeted compliance review
  3. Extended compliance audit or investigation

CMS may not request documentation when hospitals submit the initial attestation, but if the agency requests documentation as part of a targeted compliance review, hospitals may have no more than 60 days to respond. Failure to respond adequately could result in findings of noncompliance, denial of provider-based status, and/or payment recovery actions.

For each off-campus HOPD, organizations should establish a centralized electronic repository containing:

  • Attestation support files
  • Licenses
  • Organizational charts
  • Bylaws
  • Accreditation documentation
  • Referral analyses
  • Financial integration records
  • Signage photographs
  • Website screenshots
  • Enrollment documentation
  • Policies and procedures

Step 8: Monitor CMS Rulemaking and Future Guidance

Several implementation details remain unresolved, including:

  • Final documentation requirements
  • Reattestation procedures
  • Reattestation frequency
  • PECOS enrollment functionality
  • Operational specifics of CMS review processes

Hospitals should monitor regulatory developments and update plans as guidance evolves.

Final Takeaway

Hospitals should begin preparing immediately. Those that inventory their departments, obtain separate NPIs, validate operational integration, assemble supporting documentation, and maintain continuous audit readiness will be better positioned to protect both Medicare OPPS reimbursement and other provider-based revenue streams.

America's Essential Hospitals published this content on September 18, 2026, and is solely responsible for the information contained herein. Distributed via Public Technologies (PUBT), unedited and unaltered, on September 18, 2026 at 13:01 UTC. If you believe the information included in the content is inaccurate or outdated and requires editing or removal, please contact us at [email protected]