Skip to main content
Two women healthcare physicians chatting in a lobby.

Navigating Off-Campus HOPD Attestation & NPI Requirements

Learn how to prepare for off-campus outpatient department requirements effective January 1, 2028.

The Consolidated Appropriations Act, 2026 established new requirements for off-campus hospital outpatient departments (HOPDs) paid under the Medicare Outpatient Prospective Payment System (OPPS). Beginning January 1, 2028, hospitals must obtain a separate National Provider Identifier (NPI) for each applicable off-campus department, submit provider-based compliance attestations, and comply with ongoing reattestation requirements. Failure to comply may jeopardize Medicare OPPS reimbursement for services furnished in those departments and create exposure to payment recoupments for departments that do not meet provider-based requirements.

For hospitals participating in the 340B Drug Pricing Program, the stakes may be even higher. If a department cannot substantiate its provider-based status, drugs dispensed in the department are ineligible for the 340B discount.

In its proposed 2027 OPPS rule, CMS issued preliminary regulations implementing these requirements. With these regulations available, compliance, finance, revenue cycle, reimbursement, enrollment, and operational leaders should consider the following practical steps to prepare for the 2028 start date.

Step 1: Establish a Cross-Functional Provider-Based Compliance Team

Preparing for the new provider-based requirements is not a task for one single hospital function. The new attestation, NPI, enrollment, operational integration, and documentation requirements touch virtually every aspect of hospital operations for these off-campus HOPDs. Hospitals should establish a formal, cross-functional steering committee immediately to oversee the assessment, implementation, and ongoing compliance process.

At a minimum, the team should include representatives from:

  • Compliance: To lead provider-based reviews, coordinate documentation readiness, monitor regulatory developments, manage gap assessments, and oversee audit preparedness.
  • Patient Financial Services/Billing: To evaluate claim submission impacts, place-of-service requirements, charge routing, and payor-specific billing implications.
  • Reimbursement & Revenue Integrity: To assess OPPS payment implications, provider-based status requirements, Medicare enrollment issues, and potential reimbursement risks.
  • Clinical Operations & Practice Management: To validate clinical integration, physician credentialing, reporting relationships, referral patterns, signage, and patient-facing operational requirements.
  • Finance: To verify financial integration requirements, including trial balance reporting, cost reporting considerations, and departmental ownership and control structures.
  • Provider Enrollment: To manage new NPI acquisition; Provider Enrollment, Chain, and Ownership System (PECOS) updates; and attestation submissions.
  • Information Technology (IT): To evaluate how new department-level NPIs will affect registration, scheduling, billing, revenue cycle, reporting, and other enterprise systems.
  • Pharmacy & 340B Program Leadership (for Covered Entities): To assess potential implications for 340B child site eligibility and ensure provider-based documentation supports ongoing program participation.

CMS is moving toward a standardized national attestation form and process with enhanced oversight and audit capabilities, and hospitals that assign clear ownership and governance now may be better positioned to demonstrate compliance when attestations become mandatory.

Step 2: Identify All Affected HOPDs

The requirements apply to off-campus HOPDs paid under OPPS. Critical access hospitals (CAHs), Indian Health Service (IHS) facilities, Rural Health Clinics (RHCs), and Federally Qualified Health Centers (FQHCs) are excluded. Hospitals should immediately develop a comprehensive inventory of all provider-based departments and validate which locations are subject to the new requirements.

A complete inventory should include:

  • Department name
  • Physical address
  • Current CMS enrollment status
  • Existing billing NPI(s)
  • Distance from the main campus
  • State licensure status
  • 340B participation status
  • Operational ownership structure

Beginning with a good inventory and gap assessment is essential. Based on our experience working with hospitals on provider-based compliance, correcting deficiencies often takes significant time.

Step 3: Develop an NPI Implementation Strategy

One of the most significant operational changes is CMS’ requirement that each applicable off-campus HOPD obtain a separate NPI and update enrollment records in PECOS before submitting an attestation. This requirement will likely affect:

  • Patient accounting systems
  • Charge master configurations
  • Revenue cycle workflows
  • Claims editing systems
  • Scheduling applications
  • Practice management systems
  • Data warehouses
  • 340B split-billing software
  • Managed care contracting
  • Revenue integrity

Developing an IT plan is critical, because the new NPIs will affect multiple systems throughout the organization.

In addition to Medicare enrollment requirements, hospitals should carefully evaluate the potential downstream impact of department-level NPIs on managed care contracting, provider directories, authorizations, network participation, reimbursement methodologies, and payor credentialing requirements.

Step 4: Conduct a Provider-Based Compliance Gap Assessment

The new attestation process will require hospitals to certify compliance with provider-based department requirements. CMS is expected to implement increased oversight through a multitiered process that includes automated reviews, targeted reviews, audits, and, if necessary, extended compliance investigations. Hospitals should start evaluating their compliance and compiling supporting documentation across the following required categories.

Public Awareness

Patients must clearly understand they are receiving services from the hospital. Hospitals should review:

  • Exterior signage
  • Interior wayfinding signage
  • Directories
  • Appointment cards
  • Business cards
  • Websites
  • Marketing materials
  • Telephone answering protocols

Importantly, all these materials must appropriately reflect the hospital's Medicare-recognized provider name, not merely the health system brand. Our experience with prior reviews suggests CMS may evaluate websites, public-facing materials, and even how staff answer calls. 

Clinical Integration

Hospitals should confirm that:

  • Practitioners have appropriate hospital privileges.
  • Hospital leadership exercises oversight of clinic operations.
  • Providers report through hospital governance structures.
  • Patients have access to the full range of hospital services.

Potential supporting documentation includes medical staff bylaws, practitioner privilege lists, organizational charts, referral reports, patient care policies, nondiscrimination policies, and accreditation records.

Hospitals should review privilege categories carefully. Some categories, such as “courtesy” privileges, may not adequately support provider-based requirements if they place limits on the provider(s) in question.

Financial Integration

One of the most common compliance vulnerabilities involves financial integration.

Hospitals should verify that:

  • Department revenues and expenses appear directly on the hospital trial balance.
  • A separate general ledger is not maintained.
  • Financial activity is embedded within the hospital’s accounting structure.

Supporting documentation may include trial balances and charts of accounts demonstrating full financial integration. Monthly journal entries moving expenses and revenue from the clinic general ledger to the hospital general ledger are a common compliance red flag.

Ownership & Control

The department must be wholly owned and controlled by the hospital. Hospitals should confirm that:

  • The hospital maintains 100% ownership.
  • Administrative authority remains with the hospital.
  • Purchasing and contracting authority ultimately resides with hospital leadership.

Hospitals utilizing management agreements, joint operating arrangements, or other complex operating structures should evaluate whether those arrangements remain consistent with provider-based requirements.

Supporting documentation for this category may include governance documents, narratives, bylaws, current organizational charts, and purchasing authority records.

Administrative Integration

CMS expects off-campus HOPDs to operate as hospital departments rather than independent clinics.

Hospitals should evaluate:

  • Reporting structures
  • Management oversight
  • Governance reporting
  • Administrative policies
  • Management agreements

Hospitals must not merely document integration but also demonstrate that the documented reporting relationships from the clinic to the hospital executives exist in practice.

Step 5: Validate Location & Licensure Requirements

Hospitals should review each department’s location relative to the main campus to ensure it meets the 35-mile requirement or there is readily available documentation supporting an exception.

Hospitals should also verify licensure requirements. Some states permit departments to operate under the hospital’s existing license, while others require separate licensing or additional approvals. Documentation should clearly establish compliance with state requirements.

Step 6: Verify Revenue Cycle Compliance

Revenue cycle teams should conduct targeted reviews to validate:

  • Correct place-of-service coding (POS 19)
  • Claim submission practices
  • Beneficiary financial notification processes
  • Emergency Medical Treatment and Labor Act (EMTALA)-related procedures where applicable

It is crucial to validate that off-campus claims use POS 19 when appropriate, off-campus HOPDs provide Medicare beneficiaries with all required notifications, and hospitals maintain documentation supporting beneficiary financial notifications.

Step 7: Assemble an Audit-Ready Documentation Repository

Documentation readiness is crucial to successfully navigate future CMS reviews of provider-based status. CMS is expected to employ a multilevel verification structure that may include:

  1. Automated review
  2. Targeted compliance review
  3. Extended compliance audit or investigation

While the proposed rule suggests CMS will not request documentation when hospitals submit the initial attestation, the agency likely will ask most providers for some supporting documentation as part of a targeted compliance review. If CMS requests documentation, hospitals generally may have no more than 60 days to respond. Failure to respond adequately could result in findings of noncompliance, denial of provider-based status, and/or payment recovery actions. 

Hospitals should have their supporting files on hand, so they are prepared in the event CMS makes a request. For each off-campus HOPD, organizations should establish a centralized electronic repository containing:

  • Attestation support files
  • Licenses
  • Organizational charts
  • Bylaws
  • Accreditation documentation
  • Referral analyses
  • Financial integration records
  • Signage photographs
  • Website screenshots
  • Enrollment documentation
  • Policies and procedures

Step 8: Monitor CMS Rulemaking & Future Guidance

Even after the proposed rule, several implementation details remain unresolved. These include:

  • Final documentation requirements
  • Reattestation procedures
  • Reattestation frequency
  • PECOS enrollment functionality
  • Operational specifics of CMS review processes

Current proposals indicate that reattestations will occur on a cycle not exceeding five years, with additional requirements established through future rulemaking.

Hospitals should actively monitor CMS rulemaking, participate in educational programs, and update implementation plans as new guidance becomes available.

Final Takeaway

The January 1, 2028 deadline may appear distant, but hospitals should begin preparing immediately. The new requirements represent a significant shift from voluntary provider-based oversight toward a structured national attestation and verification framework with increased scrutiny from CMS and the Office of Inspector General (OIG). Hospitals that inventory their departments, obtain separate NPIs, validate operational integration, assemble supporting documentation, and maintain continuous audit readiness will be better positioned to protect both Medicare OPPS reimbursement and other provider-based revenue streams.

How Forvis Mazars Can Help With Off-Campus HOPD NPI & Attestation Requirements

Forvis Mazars is closely monitoring developments related to these requirements and is prepared to assist with inventory development, gap assessments, provider-based attestations, NPI strategy, and system readiness. Please reach out to a professional on our team if you would like support navigating these upcoming requirements or planning next steps.

See our recent webinar for more insights on the new requirements: New Provider-Based/HOPD Requirements: How to Prepare

Related FORsights

Like what you see?
Subscribe to receive tailored insights directly to your inbox.