Corporations

Netsmart: $1.75M behavioral EHR gap resolution

Netsmart Technologies, the leading EHR vendor for behavioral health organizations, paid $1.75 million after a whistleblower documented a gap between the federal EHR certification the company claimed for its platform and the capabilities of the software as deployed to Medicaid-participating providers.

Netsmart Technologies, the dominant vendor of electronic health record software serving behavioral health and human services organizations, agreed to pay $1.75 million to resolve False Claims Act allegations brought by a whistleblower who had inside knowledge of a gap between the federal EHR certification Netsmart represented its software as holding and the capabilities of the deployed product used by behavioral health providers to claim Medicaid EHR incentive payments under the HITECH Act program.DOCUMENTED

The HITECH EHR Incentive Program made substantial Medicaid payments available to healthcare providers who demonstrated meaningful use of certified electronic health record technology. Behavioral health organizations treating significant proportions of Medicaid patients used Netsmart's platform to support their meaningful use attestations. When the platform does not fully meet the certification standards it is represented as satisfying, those attestations may not be valid, and the incentive payments claimed on their basis may be improper False Claims Act violations attributable to the vendor whose misrepresentation enabled them.

Key facts
  • Netsmart Technologies paid $1.75 million to settle HITECH certification gap allegations
  • A former employee whistleblower initiated the case with inside knowledge of the certification discrepancy
  • Behavioral health providers used Netsmart's platform to claim Medicaid EHR incentive payments
  • The gap arose from differences between the tested and deployed product configurations
  • Netsmart's dominant market position amplified the certification gap's effect on the behavioral health provider sector
  • Corrective measures and provider notification were required components of the resolution

Certification Testing Versus Deployed Product

Federal EHR certification tests a specific software configuration against defined criteria established by the Office of the National Coordinator for Health Information Technology. When the deployed product differs from the tested configuration — through post-certification updates, configuration changes for specialty clinical workflows, or differences between the tested build and the production build — a gap can emerge between what certification documents represent and what the product actually does in clinical use. Providers relying on the certification have no independent means of verifying that the deployed product performs as certified; they depend entirely on the vendor's representations.DOCUMENTED

Behavioral health EHR workflows differ substantially from those of general medical practices, and adaptations made to accommodate those differences can inadvertently affect certified capabilities. Software updates designed for one clinical function may alter performance against certification test criteria in ways that are not apparent without systematic testing of every update against the full set of certified capability specifications. Maintaining certification alignment across an evolving product requires exactly that discipline — and its absence creates the type of gap the Netsmart case documented.REVIEWED

Behavioral health providers adopted the platform on the strength of the certification. Finding after the fact that the deployed configuration had gaps left them with compliance exposure they had not anticipated and no practical ability to switch platforms quickly.

Market Concentration and Provider Dependence

Netsmart's specialized focus on behavioral health created a market position with limited direct competition from other certified vendors serving the same specialty workflows. Providers seeking certified EHR technology for behavioral health clinical documentation had few alternatives, making Netsmart's certification representations particularly important — providers could not easily verify them independently and could not migrate to a competing platform without substantial disruption to clinical operations and patient care workflows.REVIEWED

Settlement Terms and Health IT Accountability

The resolution required Netsmart to take corrective measures to align deployed product configurations with certification specifications and to notify affected customers of the settlement and its terms. The settlement reinforces the enforcement principle that health IT vendors whose certified products do not perform as certified bear primary responsibility for the improper incentive payments claimed by providers using those products. This vendor-focused accountability creates financial incentives for health IT companies to maintain genuine certification alignment across their deployed product portfolio rather than treating certification as a one-time event applicable to all subsequent versions.

Health IT vendors maintaining EHR certifications across large customer bases should implement systematic processes to track the relationship between each certified product version and the configurations deployed to specific customer segments. Updates that might affect certified capabilities should be evaluated against certification test criteria before deployment rather than after. When an update is determined to affect a certified capability, the vendor faces a compliance decision: delay deployment until recertification is obtained, or deploy without the affected capability and update the certification representation accordingly.

For behavioral health providers who used Netsmart's platform during the relevant period, the settlement does not automatically trigger reimbursement obligations. The government's general position in health IT certification cases is that providers who relied in good faith on vendor certification representations bear reduced liability compared to the vendor that made the misrepresentation. Providers should preserve documentation of the specific certification representations received from Netsmart — including any written representations in sales materials, contracts, or correspondence — as this documentation may be relevant to any CMS or state Medicaid review of incentive payments claimed based on the platform's certified status. The growing body of health IT enforcement actions signals sustained regulatory focus on the vendor tier of the healthcare technology ecosystem, and the False Claims Act's qui tam mechanism provides financial incentives for insiders with technical knowledge of certification gaps to continue bringing cases of this type.

Health IT vendors maintaining EHR certifications across large customer bases should implement systematic processes to track the relationship between each certified product version and the configurations deployed to specific customer segments. Updates that might affect certified capabilities should be evaluated against certification test criteria before deployment rather than after. When an update is determined to affect a certified capability, the vendor faces a compliance decision: delay deployment until recertification is obtained, or deploy without the affected capability and update the certification representation accordingly.

For behavioral health providers who used Netsmart's platform during the relevant period, the settlement does not automatically trigger reimbursement obligations. The government's general position in health IT certification cases is that providers who relied in good faith on vendor certification representations bear reduced liability compared to the vendor that made the misrepresentation. Providers should preserve documentation of the specific certification representations received from Netsmart — including any written representations in sales materials, contracts, or correspondence — as this documentation may be relevant to any CMS or state Medicaid review of incentive payments claimed based on the platform's certified status. The growing body of health IT enforcement actions signals sustained regulatory focus on the vendor tier of the healthcare technology ecosystem, and the False Claims Act's qui tam mechanism provides financial incentives for insiders with technical knowledge of certification gaps to continue bringing cases of this type.

Have documents relevant to this story? Reach us through our tips channel.

Every Watchdog Journal investigation is built on primary documents and classified under our evidence standard.

Browse All Investigations →