What the CFPB Medical Debt Rule Changes
The CFPB's medical debt rulemaking � finalized in 2025 � represents the most significant structural change to medical debt collection since the ACA's 501(r) regulations for nonprofit hospitals. The centerpiece of the rule: medical bills may no longer appear on consumer credit reports. Consumer reporting agencies are required to remove medical debt tradelines, and creditors and collectors may not furnish medical debt data to CRAs for inclusion in consumer reports.
The rule also expanded CFPB oversight authority to reach certain medical creditor collection practices directly, not just third-party collectors. And parallel to the federal rulemaking, state attorneys general gained new enforcement authorities that further extended the compliance perimeter for healthcare creditors.
The operational implication is significant. Credit reporting has historically been one of the primary collection levers for medical debt � not because patients fear credit damage more than they fear other consequences, but because the threat of credit impact prompted engagement. Removing that tool from the workflow does not make the debt disappear. It means healthcare creditors must shift to other recovery strategies: payment plan structures that patients will actually maintain, earlier financial assistance screening to identify who is genuinely unable to pay versus who is avoiding engagement, and more substantive pre-collection outreach that creates a reason to respond beyond credit consequences.
Healthcare creditors who have relied heavily on credit reporting as a collection strategy are now managing the same portfolio with a reduced toolkit. Those who had already built diversified recovery approaches � strong financial assistance programs, proactive payment plan offers, early-stage engagement before accounts age � are better positioned. The rule accelerates a transition that was already underway in the more sophisticated parts of the industry.
Hospital vs. Physician Group vs. Dental: Different Debt Profiles
A hospital billing department, a physician group's RCM vendor, and a dental practice all generate medical debt � but the characteristics of that debt are different enough that a single collection strategy does not serve all three well.
Hospital debt carries the highest average balance and the most complex adjudication history. By the time a hospital account reaches collection, it has typically passed through insurance processing, EOB reconciliation, patient statement cycles, and (for nonprofit hospitals subject to 501(r)) a financial assistance evaluation period. The documentation trail is longer, the compliance obligations are more layered, and the time-to-collect is longer. Nonprofit hospitals operating under IRC � 501(r) must have a written financial assistance policy, must screen patients before referring accounts to collections, and are prohibited from taking extraordinary collection actions � including lawsuits, liens, wage garnishment, and now credit reporting � before completing the financial assistance determination process.
Physician group debt is moderate in balance but high in volume, and most of it is outsourced to third-party RCM vendors or collection agencies within 90 to 120 days of insurance adjudication. Physician groups that participate in Medicare and Medicaid face additional layers � balance billing restrictions for Medicare patients, specific collection limitations for Medicaid beneficiaries, and assignment of benefits rules that affect what can legitimately be collected as a patient responsibility. Compliance obligations for physician group collections depend heavily on payer mix and group structure.
Dental debt is characterized by lower balances, a higher proportion of cash-pay patients, and faster write-off cycles. Dental practices often have thinner compliance infrastructure than hospital systems, which creates risk when in-house collection activity crosses into regulated territory. Many states require specific dealer or creditor licensing for in-house installment payment arrangements � a financing arrangement that a dental practice treats as an administrative payment plan may technically require a credit license under state law.
The No Surprises Act and Its Collection Implications
The No Surprises Act, effective January 1, 2022, prohibits balance billing for out-of-network emergency care and for certain out-of-network services provided at in-network facilities. A patient who receives emergency treatment at an out-of-network hospital, or who sees an out-of-network specialist at an in-network surgery center, cannot be billed more than the in-network cost-sharing amount for those services. Any excess charge above the in-network rate is a prohibited balance bill.
Before any account enters a collection workflow, the creditor must verify that the underlying balance is not subject to an NSA dispute. The NSA's independent dispute resolution (IDR) process allows providers and payers to contest payment amounts � but while IDR proceedings are pending, the patient responsibility is not finalized. Collecting on a balance that has an open IDR dispute, or on an amount that exceeds what the NSA permits, creates federal regulatory exposure.
The workflow implication is specific: billing systems must flag NSA-eligible encounter types at the point of adjudication, not at the point of collection referral. IDR status must be tracked as a separate field alongside collection status in the account management system. Hold codes must be in place to prevent collection activity � including letters, calls, and agency placements � on any account where an NSA dispute is open or where the balance includes a potentially prohibited amount.
Healthcare creditors who lack this flagging infrastructure are collecting on NSA-protected accounts without knowing it. The enforcement risk is real: the NSA includes private right of action provisions, state AG enforcement authority, and federal agency oversight. A collection agency that receives an NSA-disputed account from a hospital that didn't flag it doesn't eliminate the hospital's exposure � it multiplies it.
Patient Financial Hardship Programs and Collection Timing
For nonprofit hospitals subject to IRC � 501(r), financial assistance is not optional � it is a condition of tax-exempt status. The 501(r) regulations require hospitals to have written financial assistance policies (FAPs), to publicize those policies to patients, and to screen patients before taking any extraordinary collection action. The definition of extraordinary collection action under 501(r) includes lawsuits, liens, wage garnishment, and � under the CFPB rule � credit reporting. Hospitals that skip the financial assistance screening step before taking these actions put their 501(r) status at risk.
For-profit hospitals and physician groups are not required by 501(r) to screen, but the regulatory and reputational environment has pushed many to adopt similar practices. State laws in several jurisdictions now mirror 501(r) requirements for hospitals regardless of tax status, extending mandatory financial assistance screening to for-profit health systems in those states.
The timing sequence matters and must be auditable. The correct sequence for a 501(r)-compliant hospital is: provide notice of FAP availability ? allow sufficient time for patients to apply (the 501(r) regulations specify a minimum application period) ? make a financial assistance determination ? only then refer accounts that have been evaluated and found ineligible to collections. Skipping or compressing any step creates compliance exposure. A hospital that refers an account to collections before the application period has closed has taken a prohibited extraordinary collection action, even if the patient never submitted an application.
The documentation challenge is real. Many hospital billing systems track financial assistance applications in one module and collection referrals in another, without a hard integration that prevents collection referral while an FAP application is open or within the application period. Manual processes to bridge this gap are error-prone at scale. Hospitals generating high volumes of collection referrals need automated workflow logic that enforces the 501(r) sequence rather than relying on staff to check compliance manually before each referral.
FDCPA Application in Healthcare Collections
Whether the Fair Debt Collection Practices Act applies to a particular healthcare collection activity depends on who is doing the collecting and in what capacity. First-party collection by the original creditor � the hospital billing its own patients � generally falls outside FDCPA's coverage. Third-party collection agencies collecting on behalf of hospitals are unambiguously covered by FDCPA. Debt buyers who purchase charged-off medical accounts are FDCPA-covered collectors.
This distinction matters because healthcare creditors sometimes structure their collections in ways that blur the first-party/third-party line � using separate subsidiaries, operating under trade names, or re-purchasing their own accounts after placement. Courts and regulators have looked carefully at these structures, and the analysis is fact-specific. Healthcare creditors who have structured their collection operations to avoid FDCPA coverage should verify that their structure withstands current legal standards.
Regulation F, effective November 2021, layered additional requirements on FDCPA-covered collectors. The 7-in-7 call cap � no more than seven calls to a consumer within a seven-day period, and no more than one call per consumer per debt within seven days of speaking with the consumer � applies to medical debt collection the same as any other consumer debt. Electronic communication opt-out rights apply. Debt validation notice requirements apply. Healthcare collection agencies that treat medical debt as categorically different from financial debt in their compliance configurations are creating exposure for themselves and for the creditors who place accounts with them.
The specific Reg F compliance points that catch healthcare collectors off guard most frequently: the validation notice timing requirements when collection begins via electronic communication, the obligation to include specific information in validation notices about the nature of the debt (including the name of the original creditor), and the requirement to provide a clear and conspicuous disclosure with the first electronic communication that the consumer can opt out of receiving further electronic communications.
State Balance Billing Laws and Their Collection Overlap
More than 30 states have enacted surprise billing or balance billing protections of their own � protections that in many cases predate the No Surprises Act, apply to state-regulated health plans that the NSA doesn't reach (including self-funded employer plans subject to ERISA, which the NSA does cover), or impose protections that are more expansive than federal law.
Some state laws prohibit balance billing entirely for emergency services, regardless of whether the patient's plan is subject to the NSA. Others cap patient cost-sharing at in-network levels for all out-of-network care, not just emergencies. The coverage and scope varies significantly: some state laws cover commercial fully-insured plans only; others extend to Medicaid managed care plans; some cover physician groups and independent practitioners while others focus on facility billing.
Before collecting any balance that may reflect out-of-network services, healthcare creditors must verify that the amount being collected is permissible under both federal law and the applicable state's balance billing statute. This is not a one-time compliance review � it requires a state-law lookup for each account based on where the services were rendered and where the patient is domiciled, because different states' laws govern different aspects of the billing relationship.
The consequence of collecting a prohibited balance bill is not just a compliance violation � in many states, the collected amount is void and subject to mandatory refund plus penalties. A creditor or collection agency that collects $500 in excess charges that turn out to be prohibited under state law may owe refund plus statutory penalties that dwarf the original collection amount. Healthcare creditors need systematic state-law validation in their collection workflow, not after-the-fact auditing.
Vendor Oversight for Healthcare Collection Agencies
Healthcare collection is a specialty practice. A general-purpose consumer collection agency that handles credit card debt, auto deficiencies, and personal loans does not automatically understand 501(r) screening requirements, NSA hold obligations, or the specific documentation requirements for medical debt disputes. Healthcare creditors that place accounts with general-purpose agencies without verifying the agency's healthcare-specific competency are creating compliance gaps that can result in 501(r) violations, NSA enforcement actions, and HIPAA breaches � and the creditor, not just the agency, is exposed.
A healthcare-specific vendor oversight program should verify several elements that standard vendor oversight programs miss. First, HIPAA compliance: medical debt data is protected health information. The business associate agreement between the creditor and the collection agency must be executed and current, the agency must have documented data security policies that meet HIPAA's technical safeguard requirements, and the creditor should verify the agency's breach history and breach response procedures. A general vendor oversight questionnaire that asks whether an agency has a "data security policy" is not adequate for HIPAA compliance.
Second, the agency must have documented workflows for NSA holds � a written procedure that prevents collection activity on accounts flagged as NSA-eligible when IDR proceedings are open, and a mechanism for receiving updated hold information from the creditor when NSA dispute status changes. Third, the agency's collectors must be trained on 501(r) requirements � specifically, that they cannot take extraordinary collection actions on accounts that have not completed the financial assistance evaluation process, and that they must route requests for financial assistance back to the originating creditor rather than treating them as a collections deflection tactic.
Complaint handling is another area where healthcare vendor oversight frequently falls short. Medical debt disputes often involve insurance adjudication questions, NSA eligibility disputes, or financial assistance claims � all of which require routing back to the creditor rather than being handled by the agency as a standard debt dispute. Agencies without healthcare-specific complaint workflows route these as generic disputes, missing the substantive issue and potentially taking collection actions that are prohibited while the underlying question is unresolved.
Building Compliant Healthcare Recovery Workflows
A compliant healthcare recovery workflow is not simply a collection workflow with additional holds. It is a sequenced decision tree where each step gates the next, and each step produces an auditable record. The sequence matters: insurance adjudication confirmation must come before patient balance is established; NSA eligibility check must come before any collection action on a potentially out-of-network balance; financial assistance screening (for 501(r) hospitals) must close before collection referral authorization is issued; IDR status verification must confirm no open dispute before any collection activity begins; state balance billing law check must validate the collectability of the specific balance under applicable state law.
Every step in this sequence must produce documentation. CFPB and state AG enforcement actions in healthcare collections frequently center on documentation gaps � the creditor or agency couldn't demonstrate that it completed required steps before taking collection action, not that it deliberately skipped them. "We think we followed the process" is not an adequate response to a regulatory inquiry. The documentation must show that each gate was cleared, with timestamps, for each account.
The practical challenge for high-volume healthcare creditors is that manual execution of this sequence is not sustainable. Billing volumes in large hospital systems generate tens of thousands of collection-eligible accounts per month. Manual compliance checking at that scale produces errors and delays � delays that extend the time before a genuinely collectible account moves to collection, and errors that allow prohibited collection actions to proceed on accounts that should be on hold.
The recovery rate gap between healthcare creditors with purpose-built compliance workflows and those managing it manually is meaningful � not because automated workflows are more aggressive, but because they resolve holds correctly and move forward confidently. Manual processes stall on uncertainty: a collector who isn't sure whether an account has cleared its 501(r) hold period defaults to inaction. An automated workflow either clears the hold based on documented criteria or escalates it for review. The accounts that are genuinely collectible get worked; the ones that need more process get flagged rather than forgotten. That distinction, at scale, is where the recovery rate difference lives.