Healthcare Debt Collection: CFPB Medical Debt, 501(r), and NSA Compliance

Healthcare Debt Collection: CFPB Medical Debt, 501(r), and NSA Compliance
Back to Insights

The Healthcare Revenue Cycle and Collections

Healthcare debt collection operates at the intersection of clinical care, insurance adjudication, and consumer finance, a combination that makes it among the most complex collections environments in the industry. Balances may reflect any combination of insurance underpayment, patient cost-sharing, charity care eligibility gaps, billing errors, and disputed charges, meaning collection attempts frequently precede full resolution of the underlying billing claim. This creates a foundational compliance challenge: collections teams must work accounts where the correct balance is not yet established.

The regulatory landscape has accelerated in complexity since 2022. Federal rulemaking under the No Surprises Act, the CFPB's medical debt credit reporting action, IRS 501(r) enforcement, and more than 30 state-level balance billing laws have collectively reshaped what healthcare providers, hospital systems, and their collection partners must do before pursuing patient balances. Organizations that apply traditional third-party collection workflows to healthcare debt without modification face material compliance and reputational exposure.

CFPB Medical Debt Credit Reporting Rules

The CFPB finalized rules in 2025 that remove medical debt from consumer credit reports, representing the most significant change to healthcare collections incentive structures in decades. Historically, credit reporting served as a powerful collection lever, consumers with good credit scores had strong motivation to resolve medical balances quickly to protect their credit standing. Under the new framework, that lever disappears for medical debt specifically.

Healthcare collections programs must adapt to a world where self-pay patients have reduced external motivation from credit consequences. This accelerates the shift toward early intervention and financial counseling models, where patient engagement during and immediately after the care encounter, before balances reach the billing department, becomes the primary recovery strategy. Organizations that had built collection workflows around eventual credit reporting need to rebuild segmentation and contact strategy logic from the ground up.

501(r) Financial Assistance Policy Sequencing

Non-profit hospitals exempt under IRS § 501(c)(3) must comply with the § 501(r) requirements governing financial assistance policies (FAP) and extraordinary collection actions (ECA). The sequence is not optional: hospitals must complete FAP screening and provide adequate notification before initiating any ECA, which includes reporting to credit bureaus, initiating legal action, placing liens, or referring accounts to third-party collectors without explicit compliance safeguards.

  • FAP Notice Requirements: Written notice of FAP availability must be provided at or before the first billing statement
  • Application Period: Hospitals must allow a minimum 240-day application period from the first billing statement before initiating ECAs
  • Plain Language Summary: A plain language summary of the FAP must accompany each billing statement and be provided upon request
  • Suspension Obligations: If a patient submits an incomplete FAP application, the hospital must suspend ECA and notify the patient of missing information
  • Third-Party Agency Contractual Requirements: Agencies receiving hospital accounts must contractually agree to comply with 501(r) requirements, including suspension of ECAs and FAP referral obligations

No Surprises Act IDR Workflow Integration

The No Surprises Act (NSA) established a federal Independent Dispute Resolution (IDR) process for out-of-network billing disputes between providers and payers, but its patient protection provisions create direct obligations that collections programs must honor. Patients who received out-of-network emergency services or certain non-emergency services without adequate advance notice cannot be billed above their in-network cost-sharing amount, and any balance in dispute through the IDR process cannot be sent to collections until the dispute is resolved.

Collections workflow systems must integrate IDR hold status from billing and claims systems in real time. Accounts flagged as NSA-protected or IDR-pending must be placed in a compliance hold that prevents contact, statement generation, and third-party placement until the IDR process concludes. Failure to implement IDR holds exposes providers to NSA violation findings, CFPB enforcement action under UDAP theories, and state unfair business practice claims, frequently with per-violation penalties that aggregate quickly across high-volume patient populations.

FDCPA: First-Party vs. Third-Party Analysis

The FDCPA applies when a third party collects a debt on behalf of another, it does not apply to providers collecting their own first-party patient balances in their own name. However, the distinction is more complicated in healthcare than in most industries. Hospital systems that operate under multiple legal entities, use internal collections units with different trade names, or engage management service organizations to perform collections on their behalf may inadvertently trigger FDCPA coverage despite an intent to collect first-party debt.

The FTC's "own name" exception requires that the collecting entity actually be the creditor and be collecting under its own name as the creditor. Shell entities, doing-business-as names, or collection units operating under different consumer-facing names from the billing entity may be treated as third-party collectors subject to the full FDCPA framework. Healthcare organizations should conduct a legal entity analysis of their collections operations before assuming FDCPA exemption applies.

State Balance Billing Laws

The NSA provides a federal floor on out-of-network billing protections, but more than 30 states have enacted their own balance billing laws, many of which are stronger than the federal standard. State laws vary significantly on which provider types are covered, which insurance products are subject to protection, and what dispute resolution mechanisms apply. Collections programs operating across multiple states must maintain a current state-law matrix that maps each patient account to the applicable state protections.

Key dimensions of state variation include: whether the law covers self-funded ERISA plans (most states cannot regulate these under federal preemption, making the NSA the sole protection); whether the law applies to ground ambulance services (excluded from the NSA but covered in some states); and whether state IDR timelines differ from the federal 30-business-day timeline. Placing a disputed NSA or state balance-billing account with a third-party agency before state-required dispute resolution is complete represents one of the highest-risk compliance failures in healthcare collections.

HIPAA Business Associate Agreements

Collection agencies, law firms, and analytics vendors that access protected health information (PHI) on behalf of healthcare providers are business associates under HIPAA and must execute a Business Associate Agreement (BAA) before accessing any patient data. The BAA must specify permissible uses and disclosures of PHI, require appropriate safeguards, mandate breach notification, and restrict subcontracting to other business associates who have agreed to equivalent protections.

  • Minimum necessary standard: Collection agencies should receive only the PHI necessary to perform collection functions, typically name, address, account balance, date of service, and insurance status. Clinical information should not be transmitted unless specifically required
  • Breach notification: BAAs must require the business associate to notify the covered entity within 60 days of discovery of a breach of unsecured PHI
  • Return or destruction: At termination, the agency must return or destroy all PHI received under the agreement
  • Subcontractor chains: If the collection agency uses a subcontractor (credit bureaus, letter vendors, skip tracers) who will access PHI, those subcontractors must also execute BAAs

Building a Compliant Healthcare Collections Program

Healthcare collections programs that achieve both compliance and recovery performance share a common architecture: 501(r) and NSA eligibility screening happens before any account enters the collections workflow, not as a reactive check when compliance issues surface. Patient financial counseling and FAP application periods run concurrently with early-stage contact, preserving recovery opportunities while satisfying pre-collection obligations. Third-party agency contracts include explicit 501(r) compliance representations, BAA execution, and right-to-audit provisions.

Analytics platforms built for healthcare integrate eligibility screening, FAP application tracking, IDR hold status, state law compliance matrices, and collection performance data into a unified workflow. This eliminates the dangerous gap between billing systems (which know regulatory status) and collections systems (which historically operated without that context). Organizations that bridge this gap recover more, spend less on compliance remediation, and face materially lower regulatory risk across the increasingly complex healthcare collections landscape.

Related Solution

Compliance & Risk

Real-time regulatory monitoring, automated audit documentation, and workflow enforcement that keeps pace with evolving healthcare-specific compliance requirements.

See the Compliance Platform