What the No Surprises Act Covers
The No Surprises Act was signed into law in December 2020 as part of the Consolidated Appropriations Act and took effect January 1, 2022. It applies to providers, facilities, and health plans subject to federal group market requirements — including most employer-sponsored plans and individual/family plans purchased through the marketplace. The full regulatory framework and model notices are maintained by CMS at cms.gov/priorities/key-initiatives/no-surprises-act.
The Act protects patients from unexpected out-of-network bills in three specific situations:
- Emergency services — at any facility, regardless of the provider's network status. Providers cannot balance-bill patients beyond their in-network cost-sharing for emergency services.
- Non-emergency services at in-network facilities — where the patient did not have a meaningful choice of provider (ancillary providers like anesthesiologists, radiologists, assistant surgeons, and hospitalists rendering services at an in-network hospital).
- Air ambulance services — from HPPS-regulated air ambulance providers.
The Act does not apply to ground ambulance services, dental and vision services provided under separate plans, or out-of-network services where the patient was given proper advance notice and voluntarily chose an OON provider using the correct consent form.
Good Faith Estimates: Who, When, and What
Good Faith Estimates (GFEs) are written cost estimates that providers must give to uninsured and self-pay patients before scheduled non-emergency services. This is one of the most operationally significant changes the NSA introduced — it requires a front-end administrative step that many practices were not performing before 2022.
Who must receive a GFE: Any patient who is uninsured or who will not be using their insurance for the service (self-pay). Insured patients also have the right to request a GFE, though the mandatory GFE requirement applies specifically to uninsured/self-pay patients.
Timing requirements (per CMS Good Faith Estimate requirements):
- Service scheduled at least 3 business days in advance: GFE must be provided at least 1 business day before the service
- Service scheduled at least 10 business days in advance: GFE must be provided at least 3 business days before the service
- Service requested but not yet scheduled: GFE must be provided within 3 business days of the request
What must be included in the GFE: Your NPI, TIN, service description (CPT/HCPCS codes), expected ICD-10 diagnosis codes, expected charges for each item or service, any expected facility fees, and contact information for any co-providers you are aware of who will bill separately (such as an anesthesiologist or lab). The GFE must be in writing and can be delivered on paper, by email, or through a patient portal.
If the actual charges exceed the GFE by more than $400, the patient can initiate a patient-provider dispute resolution process. This is a separate process from the IDR process used for payer disputes.
Balance Billing Rules and Consent Requirements
For services covered by the NSA's balance billing protections, the maximum amount a patient can be billed is their in-network cost-sharing (deductibles, copays, coinsurance) — regardless of the provider's actual charges or negotiated OON rates.
When consent to balance billing is permitted: For non-emergency services at in-network facilities, a provider may bill at OON rates if — and only if — the patient signs a valid consent notice. The consent must use the CMS-approved model notice, be signed at least 72 hours before the service (or at the time of scheduling if scheduled within 72 hours), and clearly state the anticipated OON charges and the patient's estimated in-network cost-sharing comparison.
When consent is never permitted (prohibited services): Emergency services cannot be consented to OON billing under any circumstances. Additionally, CMS has identified specific ancillary service categories for which consent cannot be obtained even at in-network facilities, including services from anesthesiologists, assistant surgeons, hospitalists, intensivists, radiologists, and pathologists at in-network facilities.
A common compliance failure: collecting OON consent forms at the front desk as part of a general intake packet — without ensuring the form meets NSA requirements, is signed 72 hours in advance, includes the correct cost estimates, and is not collected for a prohibited service category.
Required Public Notices and Disclosures
The NSA requires providers and facilities to post patient rights notices in two locations:
- Physical location: In a clearly visible location in your office or facility — your waiting room, front desk, or check-in area
- Website: In a prominent location on your public-facing website
CMS provides a model notice that satisfies this requirement. The notice must include: a description of the balance billing protections, how patients can dispute a bill they believe violates the NSA, and contact information for CMS and any applicable state consumer assistance program.
Billing statements sent to patients must also include language informing the patient of their NSA rights and directing them to CMS resources if they believe the bill is incorrect. CMS updates model notices periodically — subscribe to CMS listservs or check the CMS No Surprises Act page to receive update notifications.
Independent Dispute Resolution (IDR) Process
When you and a health plan cannot agree on payment for an NSA-qualifying out-of-network service, the federal IDR process is available to either party via the CMS IDR portal. This is distinct from the patient-provider dispute process — IDR resolves billing disputes between providers and health plans, not between providers and patients.
IDR timeline:
- Open negotiation period: 30 business days from the initial payment or denial
- If unresolved: either party can initiate IDR within 4 business days of open negotiation ending
- Certified IDR entity selection: within 3 business days
- Both parties submit offers and supporting documentation
- IDR entity selects one offer (baseball arbitration — no split decisions)
The IDR entity must select the offer closest to the Qualifying Payment Amount (QPA) — the plan's median in-network rate — unless the other party demonstrates that additional information justifies a different outcome. Credentialing, training, quality measures, complexity of services, and market conditions are permissible factors. Document these factors thoroughly in your IDR submission.
IDR entities charge administrative fees split between the parties. The losing party typically pays both parties' IDR fees. Since 2022, provider success rates in IDR have been substantial — many providers have successfully argued above-QPA rates for complex, high-cost procedures with supporting documentation.
Penalties for Non-Compliance
Violations of the NSA balance billing protections are subject to civil monetary penalties. CMS can investigate complaints and impose penalties of up to $10,000 per violation (CMS No Surprises Act enforcement). State insurance commissioners may also have concurrent enforcement authority under applicable state law.
Failure to provide a required Good Faith Estimate, collecting invalid consent forms, balance billing a patient for a prohibited service, and failing to post required notices are all individually penalizable violations. A patient who receives a bill they believe violates the NSA can file a complaint with CMS at cms.gov/nosurprises.
Repeated violations can also trigger corrective action plans, exclusion from federal health programs, and referral to the OIG. The practical risk is lower for practices with high Medicare/Medicaid volume (where NSA issues rarely arise) and highest for practices with significant OON commercial volume — particularly specialties like anesthesiology, radiology, emergency medicine, and hospitalist medicine.
NSA Compliance Workflow Checklist
- Identify which services trigger NSA obligations — map all service lines against the three NSA trigger categories and identify all ancillary provider relationships that may create co-provider billing obligations
- Implement GFE workflows — for all uninsured/self-pay patients, with correct timing, required data elements (CPT, ICD-10, NPI, TIN, expected charges), and documented delivery
- Audit your consent forms — verify any OON consent forms meet the CMS model notice requirements, are signed 72+ hours before the service, and are not used for prohibited service categories
- Post required notices — physical location and website; retain CMS model notice and update whenever CMS revises it
- Train billing staff on IDR — know the timeline (30-day open negotiation → 4-day IDR initiation window) and document supporting factors (credentials, complexity, market data) for any case likely to go to IDR
- Update billing statement language — ensure patient-facing statements include NSA rights disclosure
- Monitor CMS guidance — NSA regulatory interpretation has been subject to ongoing litigation and agency guidance updates; subscribe to CMS updates and review annually