If you're a physician looking to start a practice in Hawaii, or an investor eyeing the islands' healthcare market, you've probably heard the phrase "corporate practice of medicine" thrown around like a warning sign. Here's the thing — most people don't actually know what it means in Hawaii. They've read a blog post about California or Texas and assume it works the same way everywhere. It doesn't.
Hawaii has its own statutory framework, its own enforcement history, and its own practical realities. In practice, getting this wrong doesn't just mean a strongly worded letter. It can mean losing your license, unwinding an entire business structure, or watching a deal collapse at the closing table The details matter here..
Let's walk through what the prohibition actually says, how it works in practice, and what structures actually hold up.
What Is Corporate Practice of Medicine in Hawaii
The core concept is straightforward: only licensed physicians can practice medicine. A corporation — or any non-physician entity — cannot. But Hawaii doesn't just rely on common law like some states. It wrote the rule into statute Most people skip this — try not to. Which is the point..
Hawaii Revised Statutes § 453-2 defines the practice of medicine broadly. Diagnosing, treating, operating, prescribing — all of it. Then HRS § 453-3 makes it a misdemeanor for anyone to practice medicine without a license. Put those together and you have the foundation: if a corporation is effectively practicing medicine through employed physicians, both the corporation and the physicians could be in violation Most people skip this — try not to..
But the statute doesn't stop there. HRS § 453-14 specifically prohibits fee-splitting between physicians and unlicensed persons or entities. That's the provision that gets cited most often when the state goes after MSO arrangements that look too much like the corporation is sharing in professional revenue Nothing fancy..
Here's what makes Hawaii different from, say, New York or Florida: the medical board has historically taken a functional approach. Because of that, they look at who controls clinical decisions. Who hires and fires the doctors? Who sets the protocols? Who owns the patient charts? If the answers point to the non-physician entity, the board doesn't care what your operating agreement says And it works..
The "Friendly PC" Model — And Why It's Risky Here
You'll see attorneys recommend the "friendly PC" structure: a professional corporation owned by a nominal physician shareholder, with a management services agreement (MSA) funneling revenue to the MSO. In theory, the PC practices medicine. The MSO handles billing, staffing, real estate, IT, marketing — everything non-clinical Turns out it matters..
In Hawaii, this structure faces two specific pressure points.
First, the management fee. That's why if it's a fixed percentage of collections — say 85% — the board will almost certainly characterize that as fee-splitting. So they've done it before. The safer approach is a fair market value fee for specific, documented services with receipts, time logs, and benchmarking data. But even then, you're not bulletproof.
Second, control provisions. Consider this: if the MSA gives the MSO authority over hiring clinical staff, selecting EMR systems with clinical implications, setting treatment protocols, or terminating the physician owner — that's practicing medicine through a proxy. Hawaii courts and the board have looked through those provisions.
Why It Matters / Why People Care
You might be thinking: *plenty of practices operate this way in Honolulu and nobody's shut them down.Even so, enforcement has been sporadic. Worth adding: * True. But that's changing.
Three factors are converging:
Private equity scrutiny. The FTC and state AGs are investigating roll-ups nationwide. Hawaii's congressional delegation has asked for federal oversight of corporate healthcare consolidation. If you're building a platform with exit potential, your buyers' diligence teams will tear apart your CPOM structure. A shaky MSA kills deals.
Telehealth expansion. Post-COVID, mainland companies are hiring Hawaii-licensed physicians to serve patients across the islands — often through MSO structures that were never vetted by local counsel. The board has issued advisory opinions warning that out-of-state entities employing Hawaii physicians may violate CPOM if they control clinical operations.
Disgruntled physician exits. Most enforcement actions don't come from proactive audits. They come from a physician who leaves, feels wronged, and files a complaint. The board investigates. If your structure doesn't hold up, you're exposed Which is the point..
And here's the practical reality: unwinding a non-compliant structure after the fact is exponentially more expensive than building it right the first time. We're talking six-figure legal fees, potential license discipline, and sometimes complete business dissolution.
How It Works — Structuring That Actually Holds Up
There's no single "approved" structure. But there are patterns that survive scrutiny. Let's break down the components.
1. The Professional Entity Must Be Genuinely Physician-Owned and Controlled
Not "nominally." Genuinely. That means:
- The physician shareholder(s) hold 100% of equity. No phantom shares, no options for the MSO, no convertible notes that could flip control.
- The physician board makes all clinical decisions. Hiring/firing clinical staff. Protocol approval. Quality oversight. Credentialing. Peer review.
- Corporate minutes reflect actual physician governance. Not boilerplate. Real discussions, real votes, real dissent sometimes.
If you're a solo physician starting a practice, this is easy. That's why you are the PC. If you're a group, you need a real governance structure — bylaws, regular meetings, documented decisions.
2. The MSA Must Be a True Arms-Length Services Agreement
Not a revenue-sharing mechanism. A services agreement Easy to understand, harder to ignore..
What the MSO can legitimately provide:
- Billing and coding (with the PC retaining final sign-off on claims)
- HR administration for non-clinical staff
- Real estate lease management
- IT infrastructure (hardware, networking, cybersecurity — not clinical software selection)
- Marketing (with physician review of all clinical claims)
- Supply chain management for non-pharmaceutical supplies
- Compliance program administration (HIPAA, OSHA, billing compliance)
What the MSO cannot control:
- Clinical hiring/firing
- Treatment protocols
- Formulary decisions
- Patient scheduling policies that affect clinical access
- Medical record ownership or access
- Quality metrics tied to clinical outcomes
The fee structure is where most arrangements fail. Worth adding: ** Full stop. Yes, it's more administrative work. Here's the thing — the safer model: cost-plus or fair market value per service line, documented with third-party benchmarking. **Percentage-of-collections fees are presumptively fee-splitting in Hawaii.No, you can't skip it Small thing, real impact. But it adds up..
3. The Lease and Asset Structure Matters
If the MSO owns the real estate and leases to the PC — fine, if the lease is fair market value and the PC can terminate without penalty. Plus, if the MSO owns the medical equipment and "licenses" it to the PC — risky. The board has viewed equipment control as operational control Worth keeping that in mind..
No fluff here — just what actually works.
Cleaner: the PC owns or leases its own assets. The MSO provides management services, not asset control That's the part that actually makes a difference. And it works..
4. Insurance and Liability Alignment
The PC must carry its own malpractice insurance. The MSO carries its own general liability, cyber, and E&O. The MSA should include mutual indemnification — but the PC cannot indemnify the MSO for the MSO's own negligence in a way that looks like the MSO is insuring clinical risk.
5. Data and Records Ownership
Patient records belong to the PC. Always. The MSA can
6. Data and Records Ownership
The electronic health record (EHR) is the single most valuable asset of a medical practice. It must remain under the exclusive control of the PC. The MSA should therefore spell out, in unequivocal terms, that:
- All patient‑level data—including notes, orders, results, and imaging—are owned by the PC and may be copied only for legitimate operational purposes (e.g., billing, backup, disaster recovery).
- The MSO is prohibited from using, disclosing, or monetizing that data for any purpose unrelated to the provision of the agreed‑upon services.
- Any data extracts that the MSO receives must be returned or destroyed upon termination of the agreement, unless a separate data‑use agreement expressly permits continued analysis.
A well‑drafted data‑use clause protects the practice from unauthorized secondary uses and satisfies the Office for Civil Rights’ expectations under HIPAA.
7. Termination Triggers and Transition Protocols
Because MSO‑PC relationships are often long‑term, a clear exit strategy is essential. The agreement should enumerate specific termination events, such as:
- Material breach of any covenant (e.g., unauthorized control of clinical decisions).
- Failure to maintain required licenses or insurance.
- A change of ownership or control of the PC that would materially alter its governance structure.
Each trigger must be accompanied by a defined cure period and a transition plan that includes:
- A hand‑off schedule for all clinical and administrative functions.
- A data‑migration protocol that ensures uninterrupted patient access to records.
- A wind‑down of billing and collections activities that complies with state and federal reporting obligations.
By pre‑negotiating these steps, both parties avoid the chaos that can arise when a partnership ends abruptly.
8. Dispute Resolution and Governance Oversight
Even with the most meticulous drafting, disagreements arise. The MSA should therefore embed a tiered dispute‑resolution mechanism:
- Good‑faith negotiation – a mandatory 30‑day period in which designated senior representatives attempt to resolve the issue informally.
- Mediation – an independent mediator selected jointly from a pre‑approved list, with costs shared equally.
- Arbitration – binding arbitration under the rules of the American Arbitration Association, limited to matters of contract interpretation, with the arbitrator’s award final and enforceable.
Separately, the agreement should create a joint governance committee composed of an equal number of physician representatives from the PC and independent directors from the MSO. This committee meets quarterly to review performance metrics, audit findings, and any proposed amendment to the service scope. Its minutes become part of the official corporate record and serve as a safeguard against unilateral decision‑making Still holds up..
9. Compliance Safeguards and Auditing Rights
Because the MSO may handle large volumes of claims and personal health information, the MSA must contain strong compliance provisions:
- The MSO must maintain a written HIPAA compliance program that mirrors the PC’s policies, with annual independent audits.
- The PC retains the right to conduct on‑site audits of the MSO’s billing, coding, and data‑security practices, with reasonable notice and the ability to terminate the audit if non‑compliance is discovered.
- Any overpayments identified during an audit must be promptly disclosed to the appropriate government agencies, with the PC bearing responsibility for repayment and reporting.
These safeguards align the parties with the Stark Law and Anti‑Kickback Statute expectations of regulators, reducing the likelihood of enforcement action Took long enough..
10. Checklist for Physicians and Administrators
Before signing an MSA, the PC’s leadership should run through the following items:
| Item | Why It Matters |
|---|---|
| Governance clauses that explicitly reserve clinical decision‑making for the PC board | Prevents hidden control mechanisms |
| Fee structure limited to cost‑plus or FMV per service, with third‑party benchmarking | Avoids fee‑splitting pitfalls |
| Data‑ownership language that places all PHI under PC control | Protects patient privacy and regulatory compliance |
| Termination and transition plan with defined cure periods | Provides a clear exit path |
| Audit rights and compliance monitoring obligations | Ensures ongoing adherence to law |
| Independent legal review of the entire agreement | Catches subtle anti‑kickback or Stark issues early |
Worth pausing on this one Simple, but easy to overlook..
A disciplined review process not only safeguards the practice today but also builds a defensible foundation should regulators ever scrutinize the relationship.
Conclusion
An MSO can be a powerful ally for a medical practice seeking administrative efficiency, but only when the partnership is framed with crystal‑clear boundaries between business services and clinical authority. By embedding unambiguous governance provisions, a services‑only fee model, strict data‑ownership rules, and a solid exit strategy, physicians can protect both their professional autonomy
and their patients’ trust. To sustain that protection over the life of the agreement, practices should institute a living‑governance framework that treats the MSA as a dynamic contract rather than a static document.
Ongoing Monitoring and Performance Review
- Establish a joint steering committee that meets quarterly to review service‑level metrics, financial statements, and compliance reports.
- Require the MSO to submit a standardized dashboard that tracks claim denial rates, turn‑around times, and any incidents of data breach or privacy concern.
- Tie a portion of the MSO’s variable fees to predefined performance thresholds (e.g., maintaining a denial rate below industry benchmarks) so that financial incentives remain aligned with quality outcomes rather than volume‑driven motives.
Training and Cultural Alignment
- Mandate annual HIPAA, Stark, and Anti‑Kickback training for all MSO staff who interact with the practice’s data or billing functions.
- Conduct joint workshops that clarify the PC’s clinical protocols, ensuring that administrative staff understand the rationale behind workflows and do not inadvertently influence clinical decisions.
- Encourage cross‑shadowing opportunities where physicians spend a day in the MSO’s billing office and MSO managers observe clinical rounds; this builds mutual respect and reduces the risk of “shadow control” allegations.
Technology and Data Governance
- stipulate that any practice‑management or electronic health record (EHR) modules hosted by the MSO must be configurable to enforce the PC’s clinical rules (e.g., order sets, alerts) without allowing the MSO to modify them unilaterally.
- Require encryption at rest and in transit, multi‑factor authentication, and regular penetration testing, with results shared transparently with the PC’s compliance officer.
- Define a data‑retention and deletion schedule that complies with state medical record laws and gives the PC the ability to export all PHI in a usable format upon termination.
Exit Strategy Refinement
- Detail a step‑by‑step transition plan that includes a 90‑day knowledge‑transfer period, during which the MSO trains the PC’s internal team or a designated successor vendor on all ongoing processes.
- Include a provision for an independent third‑party auditor to validate that all PHI has been returned or destroyed and that any outstanding liabilities (e.g., unpaid claims, overpayments) are settled before the contract is formally closed.
- Allow the PC to retain a limited “run‑out” period for claims submitted before termination, ensuring continuity of revenue without creating a lingering financial entanglement.
Legal Prudence and Documentation
- Keep a master file of all amendments, waivers, and side letters, each signed and dated by authorized representatives of both parties.
- Schedule an annual legal “health check” where external counsel reviews the MSA against the latest regulatory guidance (e.g., OIG advisory opinions, CMS updates) and recommends any necessary revisions.
- Document any instances where the PC exercised its audit rights or termination clauses, creating an evidentiary trail that demonstrates proactive compliance oversight.
By embedding these mechanisms into the MSA—and revisiting them regularly—physicians transform a potentially risky outsourcing arrangement into a transparent, accountable partnership that enhances operational efficiency while safeguarding clinical independence and regulatory compliance Worth knowing..
Conclusion
A well‑crafted Management Services Agreement can deliver the administrative scale and cost savings that modern medical practices need, but only when the contract unmistakably separates business support from clinical authority. Precise governance clauses, a cost‑plus or fair‑market‑value fee structure, explicit data‑ownership terms, strong audit and compliance rights, and a clear, enforceable exit plan form the backbone of a defensible MSO relationship. Even so, complemented by ongoing performance monitoring, joint training, stringent technology safeguards, and diligent legal oversight, these provisions protect the practice’s professional autonomy, patient trust, and regulatory standing. When physicians and administrators approach the MSA with this level of detail and vigilance, they secure a partnership that drives efficiency without compromising the core values of medical care Simple as that..
Not obvious, but once you see it — you'll see it everywhere.