Hospitals Must Re-ID Every Off-Campus Department by 2028. The AI Doing That Work Is a HIPAA Project.
Frenkie
· 5 min read

Here is the deadline nobody in health-tech is talking about yet: by January 1, 2028, Medicare stops paying for services at any off-campus hospital outpatient department that doesn't bill under its own separate NPI with a current provider-based attestation on file. That's Section 6225 of the Consolidated Appropriations Act, 2026 — signed February 3, 2026 — and CMS is writing the implementation rules right now.
Look, this reads like a billing story. It isn't. It's a two-year, PHI-saturated data migration across every large health system in America — and the AI tools that will do most of the paperwork are a compliance project of their own.
What exactly does the law require?
Two layers matter, and they have different levels of certainty:
Requirement | Status | Source |
|---|---|---|
Each off-campus outpatient department must obtain and bill under its own NPI, separate from the hospital's | Final (statute) — effective Jan 1, 2028 | CAA 2026, §6225 |
Initial provider-based attestation (42 C.F.R. § 413.65 compliance) within the 2 years before services are billed | Final (statute) | CAA 2026, §6225 |
Ongoing attestations on a recurring schedule | Final in principle; schedule TBD by CMS | Forthcoming rulemaking |
"Off campus" = more than 250 yards from the main campus and any remote location; new 42 C.F.R. § 419.23 no-payment rule; PECOS updates before attestation | Proposed — CY 2027 OPPS rule; comments close Aug 31, 2026 | CMS proposed rule |
Applies to ALL off-campus departments paid under OPPS, including excepted/"grandfathered" ones | Final (statute) | CAA 2026, §6225 |
Miss the deadline and the penalty is total: no Medicare payment for that location, plus recoupment risk on audit.
Why is this secretly a data problem?
Because an NPI isn't a number — it's an identity wired into everything. The American Hospital Association's own comment letter lists what each new NPI must be coordinated with: electronic health records, billing platforms, payer credentialing, 340B pharmacy database enrollment, e-prescribing and pharmacy networks, PBM agreements, health information exchange participation, and government and research registries.
Multiply that by every off-campus department. A large system with 80 off-campus sites is looking at 80 new identities propagated through a dozen systems each — roughly a thousand integration touchpoints, each carrying patient data, on a fixed federal deadline. Hospitals attempting this voluntarily have already told the AHA the process varies wildly across Medicare contractors.
Nobody does that migration by hand in 2026. They'll use AI: extracting location and service data from enrollment records, drafting attestation documentation, validating claims mappings, reconciling identities across systems.
Where does HIPAA meet the AI doing this work?
At four specific points. Each one has a rule that predates AI and applies to it anyway:
Any AI vendor that touches PHI needs a Business Associate Agreement. Feeding claims data, enrollment records, or remediation spreadsheets into an LLM API without a BAA is a HIPAA violation regardless of how helpful the output is. Consumer AI tools and default API tiers generally don't come with one.
Minimum necessary applies to training and context windows. An AI agent remapping billing identities needs location and claims metadata — it almost never needs patient names, diagnoses, or clinical notes. Redact before the model sees the data: Presidio (open source), Private AI, Nightfall, and Skyflow exist for exactly this pattern.
De-identification has a legal definition. "We removed the names" is not HIPAA de-identification; Safe Harbor's 18 identifiers or Expert Determination is. NPI remediation datasets full of dates of service and locations rarely qualify without real work.
Audit trails must survive the automation. When an attestation is challenged in 2029, "the AI prepared it" is not documentation. Log which system produced which artifact from which source data — an AI inventory tool (Credo AI, Trustible) gives compliance teams that registry.
What's the lesson from this year's compliance scandal?
But here is the part that should actually worry compliance officers. Attestations are compliance evidence — a hospital swearing its department meets 42 C.F.R. § 413.65. The strongest cautionary tale of 2026 is the Delve saga: a startup accused (allegations it denies, unresolved) of generating compliance documentation faster than the underlying facts could support.
Analytical insight (our read, clearly labeled): the same failure mode is available to any hospital that lets AI draft attestations. The model will happily produce a compliant-sounding attestation for a department that doesn't actually meet the licensure, integration, or control requirements. AI should accelerate evidence collection — pulling licenses, org charts, financial integration records — while a human signs the conclusion. Any workflow where the conclusion is generated before the evidence is assembled is the Delve pattern with a hospital's Medicare revenue attached.
Who should do what, by when?
If you're a health system: inventory every off-campus location against the 250-yard definition now; the two-year attestation window means work must start in 2026, not 2027. Vet every AI tool in the remediation workflow for a BAA and a redaction layer before it touches a single record.
If you're a health-tech or RCM automation vendor: this is a genuine product window — but "HIPAA-compliant AI" is a checkable claim. Sign BAAs, architect PHI out of prompts, and expect your hospital customers to run the vendor checklist our readers already use. NIST AI RMF mapping and a listing in a vendor-neutral directory beat a landing-page badge.
If you're a compliance lead buying AI for this: run candidates through our Finder and demand the audit-trail answer in writing.
Your Action Plan
Before August 31, 2026: if implementation details affect you, comment on the CY 2027 OPPS proposed rule — the attestation cadence and process are still being decided.
This quarter: build the off-campus location inventory and gap-check each site against 42 C.F.R. § 413.65 — with humans owning the conclusions.
Before any AI touches the data: BAA signed, redaction layer in place, logging on.
By mid-2027: NPIs obtained, PECOS updated, initial attestations drafted — leaving buffer for Medicare-contractor inconsistency the AHA has already documented.
January 1, 2028: the no-payment rule takes effect. Verify final requirements against the finalized CMS rule and the Federal Register, not summaries — including this one.
The open question: whether CMS's final rule (expected late 2026) softens the cadence or holds the line. Either way, the deadline in the statute doesn't move.
Regulatory details described as "proposed" may change in the final CMS rule. This article is informational, not legal or compliance advice. Data as of July 22, 2026.
