In this article:

Healthcare M&A Due Diligence: What Buyers of Providers and Health Tech Check

M&A
/
August 22, 2026
Healthcare M&A Due Diligence: What Buyers of Providers and Health Tech Check

Healthcare M&A due diligence runs every workstream a standard deal runs, then adds the ones that make healthcare different: regulatory exposure under the Stark Law, the Anti-Kickback Statute, and the False Claims Act; billing and coding accuracy, because revenue that was billed wrong is revenue that can be clawed back with penalties; HIPAA and security posture, because protected health information is the most regulated data a company can hold; licensure, enrollment, and change-of-ownership mechanics that decide whether the acquired revenue keeps flowing after close; and payer contracts that may not follow the business to its new owner. The buyer universe spans health systems buying physician groups and ambulatory sites, private equity platforms consolidating specialties, payers buying providers, and strategics buying health technology. The workstreams below apply across all of them, weighted differently by target type.

Regulatory exposure: Stark, Anti-Kickback, and the False Claims Act

The Stark Law prohibits physicians from referring Medicare patients for designated health services to entities they have a financial relationship with, unless an exception applies, and it is a strict liability statute: intent does not matter. The Anti-Kickback Statute prohibits offering or receiving anything of value to induce referrals of federally reimbursed business, and it does require intent. Both feed the False Claims Act, under which claims tainted by a Stark or kickback violation become false claims carrying treble damages and per-claim penalties. Diligence therefore reviews every financial arrangement with a referral source: physician compensation and its relationship to fair market value, medical directorships, space and equipment leases with referring physicians, and joint ventures. It reviews the compliance program itself, hotline logs, prior audits, and any self-disclosures or corporate integrity agreements. Structure matters here: a stock purchase inherits historical liability, an asset purchase limits it, and the choice between them is frequently decided by what this workstream finds.

Billing, coding, and the revenue that can be taken back

Provider revenue is only as good as the claims behind it. A billing and coding review samples claims across payers and service lines and tests them for documentation support, correct code levels, modifier use, medical necessity, and compliance with payer-specific rules. Error rates above the low single digits indicate systemic risk, and the exposure is more than the sampled dollars, because the 60-day rule requires identified Medicare and Medicaid overpayments to be reported and returned within 60 days of identification, and a pattern uncovered in diligence has arguably been identified. Diligence also reviews payer audit history, recoupments, prepayment review status, and any exclusion screening gaps, since employing an excluded individual makes every claim they touched problematic. The financial workstream depends on this one: quality of earnings in a provider business is computed on net revenue after contractual allowances and bad debt, and the coding review is what tells the accountants whether the net revenue is real.

HIPAA, security, and the data the company holds

Every healthcare target is a HIPAA covered entity or business associate, and the diligence question is whether it has met the obligations that attach to that status. The Security Rule requires a documented, enterprise-wide risk analysis, and its absence is the most common finding in OCR enforcement actions and in diligence alike. The workstream reviews the risk analysis and risk management plan, the policies and workforce training, the business associate agreements with every vendor that touches PHI, breach history and notifications, and any OCR investigations or state attorney general inquiries. It then tests the technical reality against the paperwork: access controls on the EHR, encryption, logging, vendor access, and the incident response capability, because a company can hold a clean policy binder and an unpatched patient portal at the same time. Buyers of health technology companies add a product-level review: how PHI flows through the platform, whether de-identification claims meet the standard, and whether the customer BAAs the company signed are ones it can actually perform. The security findings interact with price the way they do in any technology deal, a dynamic covered in our article on SOC 2 and cybersecurity in M&A due diligence, with the added weight that healthcare breaches carry regulatory penalties and notification costs on top of everything else. Regulatory expectations for the Security Rule have also been tightening, which we cover in our note on the HIPAA Security Rule update.

Licensure, enrollment, and change of ownership

Healthcare revenue depends on licenses and enrollments that are tied to legal entities and owners, and a transaction can interrupt them. Diligence inventories every facility license, professional license, DEA registration, CLIA certificate, and accreditation, checks that each is current and held by the right entity, and maps what the transaction structure does to each. Medicare enrollment carries a change-of-ownership process, and the buyer's choice to accept or reject assignment of the seller's provider agreement determines whether it inherits the seller's overpayment liability along with uninterrupted billing. Medicaid and commercial payer enrollment follow their own timelines, and credentialing of acquired providers under the buyer's contracts routinely takes 90 to 120 days, during which revenue can stall unless the transition is planned. State-level requirements add certificate-of-need approvals in the states that still have them, corporate practice of medicine restrictions that dictate the structure a non-physician buyer can use, and pre-transaction notice or review laws that a number of states now apply to healthcare deals. Each is a closing timeline item that has to be sequenced with the deal calendar rather than discovered against it.

Payer contracts and the revenue that may not transfer

Commercial payer contracts are often the most valuable and least portable asset in a provider deal. Diligence reads every material contract for assignment and change-of-control terms, rate schedules and their expiry, value-based arrangements and their risk corridors, and termination rights. A contract that cannot be assigned forces the buyer to renegotiate under its own agreement, sometimes at worse rates, and a payer with termination-on-change-of-control has a negotiating position the seller may not have disclosed. The payer mix itself is a valuation driver: heavy government payer exposure carries rate risk and compliance exposure, and commercial concentration carries renegotiation risk. In health technology deals the equivalent is customer contract assignment, with the added wrinkle that hospital customers often hold consent rights and long procurement cycles.

Workforce, physicians, and the people who are the asset

In provider deals, the physicians and clinicians are the revenue. Diligence reviews employment agreements, compensation models and their Stark compliance, non-compete and non-solicit terms and their enforceability under state law, productivity and its trend, and any signals that key clinicians would leave on a change of control. Malpractice history, tail coverage obligations, and credentialing status per provider round out the review. Retention structure, rollover equity, employment terms, and earnouts follows directly from what this workstream finds.

Quality of earnings in a provider business

Financial diligence on a provider has its own vocabulary. Revenue is net of contractual allowances, the difference between charges and what payers actually pay, and the estimation of those allowances is where earnings quality lives. Diligence tests the allowance methodology against subsequent cash collections, analyzes accounts receivable aging by payer, and examines bad debt and charity care trends. Payer mix shifts, a growing share of government payers or a large employer contract expiring, move margin directly. Provider productivity trends, ancillary revenue, and the sustainability of any out-of-network revenue after surprise billing rules are each tested. The coding review feeds this analysis: revenue that depends on documentation the audit found weak is revenue the quality of earnings report should haircut, and the two workstreams have to be read together rather than filed separately.

Health technology targets: the added layer

For software, data, and device companies, the healthcare workstreams above apply through the customers and the data rather than through direct patient care, and a technology-specific layer sits on top: regulatory status of the product, including whether any function meets the definition of a medical device, interoperability and information-blocking compliance, security certifications customers require, and the ownership and consent basis for any clinical data the company uses, especially for model training. The technology diligence is standard; the healthcare overlay is what makes the findings expensive.

Running healthcare diligence

Healthcare deals reward buyers who sequence the regulatory, coding, and security workstreams early, because those are the ones with long remediation timelines and structural consequences. BD Emerson runs the security, HIPAA, technology, and financial workstreams through our M&A due diligence practice, alongside our HIPAA compliance practice for the Security Rule assessment, coordinating with the buyer's healthcare regulatory counsel on Stark, Anti-Kickback, and licensure. The findings arrive in one register, rated by whether each is a closing condition, a price item, or a first-hundred-days fix.

About the author

Leslie Sakal is a Managing Director at BD Emerson focused on cybersecurity, enterprise risk management, and regulatory compliance. She brings over a decade of experience advising organizations across technology, financial services, education, and other regulated industries on implementing organization-wide goals and programs that align with their broader business objectives.
Leslie Sakal
Leslie Sakal
Managing Director