If you're running a digital health company on the MSO-PC model, you've heard plenty from us this year here, here, and here about California's corporate practice of medicine crackdown. Carbon Health, Aspen Dental, the Art Center Holdings amicus brief — we've been telling you to check whether your management agreement hands the MSO too much control over clinical decisions, because that's where regulators have been focused.
CPOM is real, and it deserves the attention. But a July 29 DOJ announcement is a good reminder that it isn't the only structural risk baked into the MSO-PC model (and other healthcare arrangements that involve referral and marketing relationships). And depending on how your arrangement is built, it might not be the scariest one.
That same day, the Department of Justice declined to prosecute Campus Eye Management, the MSO in an MSO/PC arrangement providing billing and back office services to a New Jersey optometry practice and its surgery center. No charges against the company. At the same time, DOJ unsealed a seven-count indictment against Campus Eye's own founder and former CEO, E. Bruce DiDonato, alleging he ran a kickback scheme through those same entities.
DiDonato has not been convicted of anything — he's presumed innocent, and everything below is an allegation from DOJ's charging documents and declination letter, not an established fact. But what's alleged is worth understanding, because it's the other half of MSO/PC compliance that's easy to lose track of while you're focused on CPOM.
The distinction that matters: civil injunction vs. criminal indictment
Here's the comparison that should get your attention. California's CPOM enforcement this year — Carbon Health's $4.4 million settlement against the entities (plus a separate $100,000 civil penalty against co-founder Eren Bali personally), Aspen Dental's $2 million fine and compliance monitor — has been civil. Penalties, injunctions, restructuring requirements, and in Carbon Health's case individual exposure for the founder. Serious money, serious operational disruption, and it reached a person, but civil.
California's own CPOM statute (Bus. & Prof. Code § 2052) is nominally criminal too — a "wobbler" capped at three years in state prison — but CPOM enforcement against corporate MSOs runs through the civil Unfair Competition Law instead, which is why Carbon Health and Aspen Dental came out civil. So this isn't civil-only law versus criminal-only law; it's a civil enforcement mechanism against a criminal-adjacent statute versus direct federal criminal prosecution. What's different is the ceiling: DiDonato is charged with conspiracy to commit health care fraud, conspiracy to violate the Anti-Kickback Statute, two counts of substantive health care fraud (18 U.S.C. § 1347), and three counts of paying illegal kickbacks (42 U.S.C. § 1320a-7b) — federal exposure running up to ten years in prison on several of those counts, several times higher than the state wobbler's cap. That's the fee-splitting and anti-kickback side of the MSO/PC model, and it's the side with the higher ceiling.
If your compliance checklist has a CPOM section and nothing else, you're missing the arrangement with the harsher theoretical ceiling.
What actually happened, according to the indictment
From at least 2015 through March 2023, DiDonato allegedly ran a scheme through his optometry practice and its affiliated ambulatory surgery center. Patients referred by outside ophthalmologists for eye surgery were allegedly also routed through duplicative or medically unnecessary diagnostic testing — tests that, per the indictment, in most instances neither DiDonato nor the treating optometrist reviewed, and that the referring ophthalmologists didn't rely on to make treatment decisions.
The tests weren't incidental, according to the indictment. DOJ alleges DiDonato paid the referring ophthalmologists for sending him those patients, disguising the payments as "consulting fees" and flat monthly amounts that were, in substance, calculated as a percentage of what Medicare paid for the diagnostic tests performed on their referrals. If the allegations hold up, that's the classic disguised-remuneration shape under the Anti-Kickback Statute: something of value, allegedly exchanged for referrals of federal healthcare program business, dressed up in a services agreement that didn't reflect what was actually happening.
DOJ's indictment puts the fraudulent claims submitted to Medicare at roughly $3.4 million, of which Medicare actually paid out about $1 million. DiDonato allegedly used the reimbursement history to help market and sell the practice to private equity investors, which is how Campus Eye Management Holdings LLC came to exist — formed in mid-2021 ahead of the investor equity purchase closing that December, and he became CEO of the new entity.
DiDonato's role as CEO of the Campus Eye entities ended in March 2023. Separately, Campus Eye self-disclosed the underlying billing and kickback conduct to DOJ rather than staying quiet.
Why the company walked and the founder didn't
DOJ's new Department-wide Corporate Enforcement Policy (CEP), issued in March 2026, lays out the conditions under which a company can earn a declination even after criminal conduct occurred inside it. Campus Eye is the first healthcare company to get one, and the declination cites six factors: timely and voluntary self-disclosure; full and proactive cooperation, including access to legacy billing and beneficiary data; the nature and seriousness of the offense; timely and appropriate remediation (revised billing, payment, and compensation policies, new compliance personnel, compliance training, ongoing risk assessment and monitoring); the absence of aggravating factors; and agreement to compensate victims — DOJ ran an independent ability-to-pay analysis and capped Campus Eye's disgorgement at $1 million against the roughly $3.7 million total at issue, because more would have threatened the company's viability.
None of that helped DiDonato. The company's cooperation didn't just fail to protect him — the evidence Campus Eye handed over is presumably a meaningful part of the case against him now. That's the design of the CEP, stated plainly by DOJ's National Fraud Enforcement Division: reward companies that take responsibility, and use what they hand over to go after the individuals who created the exposure.
Where to look for risk in your MSO/PC structure
The fee-splitting and anti-kickback risk in an MSO/PC arrangement usually doesn't show up in the MSA between the MSO and the PC itself — most of those are drafted with fair-market-value language and a compliance-minded eye these days (at least those I’m reviewing). It shows up around the edges: in how the practice compensates referring providers, in "marketing" or "consulting" arrangements with outside physicians, and in compensation structures for anyone whose pay can be read as tracking referral volume or value, even informally.
A few things worth checking against your own structure:
- If a payment arrangement's actual math tracks the volume or value of referrals — flat fee, consulting agreement, marketing fee, whatever it's called — the label doesn't control. Regulators look at what the arrangement actually pays for. This is a different legal theory from CPOM (which is about who controls clinical decisions, not about payment for referrals), but it shares the same regulatory instinct: look past the label to what's actually happening.
- Check every referral relationship, not just the core MSA. The MSO/PC agreement is usually the most heavily lawyered document in the structure. The physician "consulting" arrangement, the marketing agreement with a referring group, the equipment lease with favorable terms to a referral source — those get less scrutiny and are exactly where this kind of exposure tends to live.
- Campus Eye's remediation included ongoing risk assessments and monitoring, new compliance personnel, and real training. If your compliance program is a document nobody has opened since it was signed, it may as well not exist at all. It might actually be better if it didn’t…
For years, voluntary self-disclosure was a factor prosecutors said they'd weigh. Campus Eye is DOJ's proof that, done right — timely, fully cooperative, backed by real remediation — the CEP can mean the difference between a declination and facing charges as a company, on top of whatever happens to the individuals involved.
Don't wait for an indictment to check your own house!
- Pull every agreement that touches a referral source — consulting arrangements, marketing agreements, medical director fees, equipment leases — and ask honestly whether the compensation tracks referral volume or value in substance, whatever it's labeled.
- Check fair market value independent of referrals. A payment can be structured as flat, tiered, or percentage-based and still violate the Anti-Kickback Statute if it isn't set at a level the parties would agree to absent the referral relationship.
- Look for safe harbor fit, not just good intentions. If an arrangement is meant to rely on a personal services, space/equipment rental, or employment safe harbor, confirm it actually satisfies every element — writing, term, aggregate compensation set in advance, and the rest. Partial compliance is not compliance.
- Have a self-disclosure plan before you need one. Campus Eye's outcome shows the CEP can mean the difference between a declination and facing charges as a company, but only for organizations that already know how to investigate, remediate, and come forward quickly when something surfaces.
CPOM and fee-splitting/anti-kickback are two of the risks built into the MSO/PC model — not the only two, and not a complete compliance checklist on their own. We'll keep covering other angles of MSO/PC compliance as they come up, so subscribe if you want to stay ahead of the next one.
Want more on how enforcement actions like this one should change what you're doing today? Subscribe to our newsletter for the latest legal and regulatory developments in digital health.




.png)

