
IT due diligence in 2026: the software licences that don't survive the sale
IT due diligence in 2026: the 8-domain checklist, the licence trap that costs buyers most, TSA timelines, and how to run it in a data room for IT due diligence.
Healthcare due diligence is the review a buyer runs on a provider, payer, medtech or health services target before closing. It covers the same financial ground as any acquisition, but its decisive findings are regulatory: licensure, billing accuracy, fraud and abuse exposure, and patient data handling.
Buyers who have done a dozen deals in other sectors tend to underestimate this one. A healthcare target can have clean audited accounts, growing revenue and a strong management team, and still carry a seven-figure refund obligation nobody has quantified. This guide covers the eight review areas, the billing trap, and how HIPAA constrains what reviewers can even look at.
Running the review means putting billing samples, payer contracts, credentialing files and compliance audits in front of reviewers who should not all see the same material. A data room for healthcare due diligence handles that with one link per party. Section 8 covers the setup step by step.
Healthcare due diligence is a structured review of a target that delivers, pays for, or supports the delivery of clinical care. It is commissioned by an acquirer or investor after a letter of intent and it produces a report covering regulatory standing, reimbursement quality, compliance history, clinical risk, and the effect of all three on the numbers in the model.
The distinguishing feature is that revenue in this sector is conditional. A dental group, an infusion centre or a home health agency does not simply sell a service and collect a price. It bills a government or commercial payer under a contract and a body of regulation, and the payment is only properly earned if the service was medically necessary, documented, coded correctly, and delivered by a credentialed provider under a lawful arrangement. Any one of those conditions failing turns collected revenue into a refund obligation.
That is why a standard financial due diligence exercise is necessary but not sufficient. Quality of earnings work confirms that the cash arrived and that the accruals are reasonable. It will not tell you whether the cash was billed under a correct evaluation and management level, whether the referring physician had a compensation arrangement that fits a Stark exception, or whether the medical director agreement priced at fair market value.
The second difference is that liability travels. In most sectors an asset purchase leaves the seller's historical liabilities behind. In healthcare, successor liability attaches through the Medicare provider agreement, through payer contract terms, and through the practical reality that a government payer can recoup from the entity currently holding the provider number.
Third, the diligence itself is regulated. A reviewer cannot simply be handed 500 patient charts. Protected health information is governed by HIPAA regardless of who wants to see it and why, so the document request has to be designed around de-identification and controlled review from the start. That constraint shapes the whole workstream, including how the data room is built.
The eight areas below make up the standard scope for a provider or health services target. Each produces findings that translate into a price adjustment, an indemnity, a closing condition, or a first-year remediation budget, and a good report expresses all four in the same units the deal model uses.
Licensure and accreditation come first because everything else is downstream of the right to operate. The reviewer confirms facility licences, professional licences for every clinician, CLIA certificates for any laboratory, DEA registrations where controlled substances are handled, and Medicare and Medicaid enrolment status. Accreditation follows, whether from the Joint Commission, AAAHC, CARF or an equivalent body, along with the most recent survey findings and any plan of correction still open. An expired certificate is easy to fix. A survey deficiency open across two cycles is a signal about the compliance culture.
Payer contracts and reimbursement come next, and this is where deal value is made or lost. The reviewer builds the payer mix, reads the fee schedules, and checks each material contract for term, termination rights, rate escalators, and above all the assignment and change-of-control clause. Billing and coding sit alongside it, followed by fraud and abuse, which carries the largest tail risk relative to the effort required to review it.
| # | Area | What the reviewer checks | Typical red flag |
|---|---|---|---|
| 1 | Licensure and accreditation | Facility and clinician licences, CLIA, DEA, survey findings | Plan of correction open across two survey cycles |
| 2 | Payer contracts | Payer mix, fee schedules, term, assignment and consent clauses | Top payer contract requires consent to assign |
| 3 | Billing and coding | Coding accuracy sample, denials, modifiers, overpayment log | Coding distribution skewed to the highest level |
| 4 | Fraud and abuse | Physician arrangements, referral sources, exclusion screening | Medical director paid above fair market value |
| 5 | HIPAA and data security | Risk analysis, BAAs, breach log, access controls, training | No security risk analysis in the past 24 months |
| 6 | Clinical quality | Credentialing files, incident log, malpractice claims, outcomes | Credentialing without primary source verification |
| 7 | Ownership structure | Corporate practice rules, MSO agreements, fee splitting | Lay ownership of a professional entity in a CPOM state |
| 8 | Workforce | Clinician contracts, non-competes, staffing ratios, agency spend | Key physicians without enforceable retention terms |
HIPAA and data security follow, covering the security risk analysis, business associate agreements, the breach log, access controls and workforce training. Clinical quality, credentialing and malpractice come next. Ownership structure covers the corporate practice of medicine rules that apply in many states and the management services arrangements built to work within them. Workforce closes the list, because in a clinician-dependent business the retention of a handful of named providers can be the largest determinant of post-close revenue.
Knowing the areas is one thing; knowing what lands in the room is another. The table below maps each area to the documents a reviewer will request, which is also the folder structure the seller should build before the room opens.
| Area | Documents requested | Typical count | Sensitivity |
|---|---|---|---|
| Licensure and accreditation | Licences, CLIA and DEA certificates, survey reports, corrections | 25 to 70 | Low |
| Payer contracts | Executed contracts, fee schedules, amendments, credentialing letters | 20 to 60 | Very high |
| Billing and coding | Claim samples, coding audits, denial reports, refund log | 30 to 90 | Very high |
| Fraud and abuse | Physician agreements, FMV opinions, exclusion screening records | 25 to 80 | Very high |
| HIPAA and data security | Risk analysis, BAAs, breach log, policies, training records | 20 to 50 | High |
| Clinical quality | Credentialing files, incident log, claims history, quality metrics | 40 to 120 | Very high |
| Ownership structure | Entity charts, MSO agreements, equity documents, state filings | 15 to 40 | Medium |
| Workforce | Clinician contracts, compensation plans, staffing schedules | 30 to 90 | High |
The sensitivity column drives how the room gets configured. Four of the eight areas are marked very high, for different reasons. Payer contracts are commercially explosive because rate schedules are the target's most valuable competitive secret and are almost always subject to confidentiality terms with the payer itself. Billing samples and credentialing files carry protected health information. Physician arrangements are the documents most likely to be read in a later government investigation. None of those four folders should share a permission set with the licensure folder.
If healthcare due diligence produces one deal-changing finding, it is usually here. Billing errors do not behave like other operational problems, because a single misunderstanding about a code or a modifier gets repeated automatically across every claim of that type for as long as the practice pattern persists. A five percent error rate discovered in a sample of 100 claims is not a five percent problem. Extrapolated across four years of claim volume, it is a refund calculation.
The mechanism that makes this urgent is the 60-day overpayment rule. Once a provider identifies an overpayment, it must be reported and returned within 60 days, and the applicable lookback period runs six years. An overpayment retained past that window is treated as an obligation under the False Claims Act, which converts an administrative refund into treble damages exposure with a per-claim civil penalty attached. Since diligence is a form of identification, the review itself can start the clock, which is why healthcare findings need to reach counsel quickly rather than sitting in a workstream tracker.
The coding audit is the technical heart of the review. A reviewer pulls a sample, re-codes it from the underlying documentation, and compares the result to what was billed. Sample size matters: the OIG self-disclosure protocol expects a minimum of 100 items where a probe indicates a systemic issue, and a sample designed only to reassure the buyer is worth very little. What the reviewer wants is the pattern rather than the occasional mistake: evaluation and management levels weighted toward the highest codes, modifiers applied routinely rather than by exception, incident-to billing where supervision requirements were not met, or units the documentation does not support.
Successor liability is the second half of the trap. In a stock deal the exposure travels with the entity by definition. In an asset deal the buyer chooses whether to accept automatic assignment of the Medicare provider agreement. Accepting it preserves the provider number and avoids a gap in billing, but carries the seller's prior overpayment and sanction exposure forward. Rejecting it means enrolling fresh, which cuts the historical tail but creates a revenue gap of several months while CMS processes the enrolment. Neither option is free.
Payer contract assignment is the third element and the one most often missed. Commercial payer contracts frequently require written consent to an assignment, and many contain change-of-control provisions that let the payer terminate or renegotiate. A target whose top two contracts both need consent has handed those payers a negotiating position on announcement day. Re-credentialing new entities and providers typically takes 90 to 180 days, so a contract that has to be re-papered rather than assigned creates a real cash flow hole.
| Finding | How it surfaces | Commercial remedy |
|---|---|---|
| Coding error rate in the sample | Re-coding a claim sample against source documentation | Price adjustment sized to the extrapolated refund |
| Unquantified overpayment exposure | Refund log, denial trends, no prior external audit | Escrow held until a full audit completes post-closing |
| Physician arrangement outside an exception | Compensation terms compared with the FMV opinion | Specific indemnity, uncapped and separately negotiated |
| Payer contract needs consent to assign | Assignment clause in the top payer agreements | Condition precedent, consent obtained before closing |
| Excluded individual on the payroll | OIG exclusion list screening against the staff roster | Immediate remediation plus a self-disclosure decision |
| Systemic billing pattern across all sites | Error repeats in every location sampled, not one | Walk away or restructure as an asset carve-out |

Billing samples and payer fee schedules go to the reimbursement specialist and counsel, not to the lender or the broker.
The commercial handling follows the quantification. A coding error rate that can be extrapolated becomes a price adjustment. An exposure that cannot be sized yet becomes an escrow with a defined release trigger. A fraud and abuse finding becomes a specific indemnity, usually uncapped and outside the general cap, because the exposure is open-ended and the insurance market treats it that way too.
Every other diligence workstream starts by asking for the documents. Healthcare diligence starts by asking which documents are even shareable. Protected health information is regulated no matter how legitimate the reason for wanting it, and a seller who bulk-uploads charts to a shared drive for the buyer's clinical reviewer has created a HIPAA problem that survives whether or not the deal closes.
The narrow path through this is the health care operations definition, which includes due diligence connected to a sale, transfer, merger or consolidation where the counterparty is or will become a covered entity. That permits some disclosure without patient authorisation, but it is narrower than buyers assume: it does not cover a private equity sponsor that will never be a covered entity, it does not cover unlimited volumes, and it does not override the minimum necessary standard. In practice most reviews run on a mix of three techniques rather than on raw records.
De-identification under the safe harbour method requires removing 18 categories of identifier, after which the data falls outside HIPAA entirely and can be analysed freely. A limited data set is the middle option: 16 direct identifiers are removed but dates and geographic detail can remain, which makes it far more useful for utilisation and payer-mix analysis, and it travels under a data use agreement rather than a business associate agreement. Redacted chart samples are the third technique, used where a clinical reviewer genuinely needs to see documentation quality rather than aggregate patterns.
Security posture is reviewed in parallel and it is not a formality. The reviewer looks for a current security risk analysis, since the absence of one is both a common finding and an independent violation. Then business associate agreements with every vendor that touches PHI, the breach log, access controls and offboarding evidence, encryption on endpoints and backups, and workforce training records. Where a target has had an incident, the question is whether notification duties were met, because HIPAA requires affected individuals to be notified no later than 60 days after discovery, with breaches affecting 500 or more people reported to HHS on the same 60-day timetable.

Chart samples and credentialing files sit in a view-only, watermarked folder with download disabled and screenshot protection on.
The acquirer inherits those obligations at closing along with everything else. That is why the security review overlaps heavily with a general cybersecurity due diligence workstream, and why healthcare buyers increasingly run the two together rather than treating HIPAA as a compliance checkbox and security as an IT problem. The practical consequence for document handling is simple: a data room for healthcare due diligence has to enforce view-only access, watermarking and per-visitor logging on the clinical folders, not merely encourage them.
Clinical review is where a buyer finds out whether the target's quality reputation is documented or merely asserted. The starting point is credentialing, meaning the file that proves each clinician was verified before being allowed to treat patients and bill for it. The reviewer checks for primary source verification of licence, education, training and board certification, National Practitioner Data Bank queries, and a recredentialing cycle that has actually been run rather than scheduled.
Exclusion screening sits alongside it and takes very little time to check. Anyone excluded by the OIG cannot be paid by a federal healthcare programme, and employing an excluded individual creates civil monetary penalty exposure for every item or service they touched. OIG guidance points at monthly screening of the exclusion list, plus state Medicaid exclusion lists where applicable, so a target that screens once at hire is carrying a gap.
Malpractice exposure comes down to what the policy actually is. A claims-made policy only responds to claims reported while it is in force, so a target with claims-made coverage needs tail coverage bought at closing or the buyer inherits the reporting gap. That extended reporting endorsement is commonly priced at 150 to 300 percent of the expiring annual premium, which is a real number in a small deal and needs to sit in the model rather than appearing as a surprise on the closing statement. Occurrence policies avoid the issue but are less common in many specialties.
The claims history itself is read for pattern rather than for count. A group of 40 physicians will have claims. What matters is whether they cluster around one provider, one procedure or one site, whether the incident log shows the events were investigated, and whether corrective action followed. A clean claims history with no incident reporting system at all is a worse signal than a handful of documented and closed claims, because it usually means nothing is being captured.
A physician platform backed by a mid-market sponsor agrees to acquire Meridian Family Health, a hypothetical nine-site primary care and urgent care group in the American Midwest with 54 million dollars of net patient revenue and 61 clinicians. The financial diligence is unremarkable. The regulatory review is where the deal changes shape.
Payer mix is the first finding that matters. Commercial plans account for 22 million dollars, Medicare for 21 million, Medicaid for 9 million, and self-pay for 2 million. That concentration means two thirds of revenue depends on government programme rules and two commercial contracts, and both of those commercial contracts turn out to contain consent-to-assign clauses.
Worked scenario. Government programmes fund 30 million dollars of the 54 million, which is why the coding audit finding is sized against Medicare and Medicaid claims first.
The coding audit is the finding that moves price. A reviewer re-codes 100 Medicare claims from source documentation and finds that 11 were billed at a higher evaluation and management level than the note supports, concentrated in three of the nine sites and in one nurse practitioner supervision arrangement. Extrapolated across the lookback period, the estimated refund exposure lands at 1.4 million dollars before any penalty.
Two further findings shape the agreement. The medical director agreement at the largest site pays 40 percent above the fair market value opinion on file, which becomes a separately negotiated indemnity outside the general cap. And exclusion screening reveals that Meridian screened at hire but never again, which turns into a closing condition requiring a full roster re-screen.
The deal closes with a 1.4 million dollar price reduction, a 2 million dollar escrow held for 24 months against the billing exposure, an uncapped indemnity for the physician arrangement, and payer consents obtained before signing rather than hoped for afterwards.
The most common mistake is treating regulatory review as a legal formality that runs after the commercial terms are set. Billing findings change price, and a 1.4 million dollar refund exposure discovered in the final week is very hard to reflect in a valuation that has already been agreed in principle. Regulatory diligence should start with the financial workstream, not after it.
The second is sampling to be reassured rather than to find out. A coding review of 15 claims chosen by the seller's billing manager tells you nothing. The sample has to be drawn independently, sized properly, and stratified across sites, providers and service lines, because the pattern is usually concentrated rather than uniform.
The third is assuming an asset deal solves the historical liability. It does not, because successor liability attaches through the Medicare provider agreement, payer contract terms and state law, and because a government payer can pursue the entity holding the provider number. The structure question and the indemnity question have to be answered together with counsel, and our legal due diligence checklist covers the wider contractual review this fits into.
The fourth is ignoring the corporate practice of medicine. In states that prohibit lay ownership of medical practices, an investor cannot simply buy the professional entity, and the management services structure built to work around that has to be examined for whether the management fee, the control provisions and the equity arrangements actually hold up. A structure that has never been tested is not the same as a structure that is sound.
The fifth is careless handling of the documents themselves. Payer fee schedules are confidential under the payer contract, credentialing files and chart samples carry PHI, and physician compensation agreements are the exact documents that get read in a later investigation. Emailing them to a lender, two advisors and an insurance broker creates exposure for both sides, and it is exposure the seller carries even if the deal dies. The same lesson applies in the adjacent IT due diligence workstream, where the material is dangerous for different reasons.
A data room for healthcare due diligence carries a heavier burden than a financial one. The financial folder holds numbers that are commercially sensitive. The clinical and billing folders hold regulated data, and mishandling them is not merely embarrassing but independently actionable regardless of whether the transaction completes.
Papermark is a secure, fully customizable, and developer-friendly data room built for modern dealmakers, with page-by-page analytics, dynamic watermarking, and transparent pricing (open-source and self-hosting available).

A healthcare due diligence data room with one folder per review area, so permissions differ by folder rather than by document.
Most healthcare diligence still runs over email and shared drives, and this is the sector where that habit carries the highest cost. There are four reasons a dedicated data room for healthcare due diligence earns its place. If you are still choosing a platform, our comparison of the best virtual data rooms covers pricing model, bidder management and compliance across the main providers.
The documents are regulated, not just confidential. Chart samples and credentialing files carry protected health information. Payer fee schedules are confidential under the payer contract itself, and disclosing them to the wrong party can breach that contract independently of anything the deal documents say. A shared drive gives you one permission set and a link that forwards. That is not an adequate control environment for material of this kind.
Six parties need six different views. Healthcare diligence is unusually asymmetric in who should see what. The reimbursement specialist needs billing samples and payer contracts. Regulatory counsel needs physician arrangements and exclusion screening. The clinical reviewer needs credentialing files and the incident log. The lender needs payer mix and financial summaries and nothing clinical at all. A data room for healthcare due diligence sets that per link, over one underlying document set.
Request lists arrive in waves and reference each other. The reviewer asks for the coding audit, reads it, then asks for the 30 underlying claims and the two supervision policies it cites. Across 300 documents and 80 open questions spread over five workstreams, an email thread loses the sequence and the same question gets asked twice by two different advisors.
The disclosure record matters years later. If a billing dispute or a government inquiry surfaces two years after closing, the question becomes what was disclosed, to whom, and on what date. A room with a per-visitor audit log answers that precisely. An inbox does not, and neither does a shared drive whose folder was later reorganised.
The rest of this section is the practical setup: five steps to build a data room for healthcare due diligence that handles all four.
Create one folder per area from the table earlier in this guide: licensure and accreditation, payer contracts, billing and coding, fraud and abuse, HIPAA and data security, clinical quality, ownership structure, and workforce. That structure is what makes differentiated access possible at all. A room organised as a flat pile of 300 files forces you to choose between giving every reviewer everything or hand-picking documents per party, and neither survives six workstreams.
Upload in bulk by dragging the folder tree straight in, then use nested folder permissions to sub-divide the clinical folder into credentialing and chart samples, which usually need different treatment. Automatic file indexing on the Data Rooms Plus plan builds and maintains the index as documents arrive, which matters here because the healthcare request list grows in waves rather than arriving complete.
This is where a healthcare room differs most from a standard M&A one. Six parties typically need six different views of the same document set, and two of those views must exclude anything carrying patient data.
| Reviewer | Folders granted | Rights |
|---|---|---|
| Regulatory counsel | All eight areas | View and download |
| Reimbursement specialist | Payer contracts, billing and coding | View only, watermarked |
| Clinical reviewer | Clinical quality, licensure | View only, watermarked, no download |
| Buyer corporate development | Payer mix, workforce, ownership structure | View and download |
| Lender | Financial summaries, payer mix | View only |
| Insurance broker | Malpractice claims history only | View only, watermarked |
Granular file-level permissions are set per link rather than per user, so each party gets its own link carrying its own folder scope, email allowlist or domain restriction, and download rule. Access is link-based, so no reviewer needs to create an account, which removes the friction that makes busy clinical advisors ignore a room entirely.

Permissions are set per link, so the lender and the clinical reviewer see different folders of the same room.
Switch the clinical quality and billing folders to view-only, disable download entirely, and turn on dynamic watermarking, which stamps every page with the viewer's email, IP address and timestamp as it renders. Screenshot protection adds a further deterrent on redacted chart samples specifically.
Pair that with an NDA agreement or a click-through confidentiality statement on the link, so every reviewer accepts terms before the first page renders and the acceptance is logged with a timestamp. The honest limit is worth stating plainly: a file that has been downloaded is legally treated as read, and no platform can recall it. That is exactly why download is disabled rather than discouraged on these folders, and why watermarking exists at all. It makes a leak traceable to a named viewer rather than merely regrettable.

Dynamic watermarking renders viewer identity onto every page, which is what makes a leak traceable to a person.
Healthcare diligence arrives in waves and the waves reference each other. The reimbursement specialist asks for the coding audit, reads it, then asks for the underlying claims and the supervision policy it cites. Run over email, that thread fragments across the practice manager, the compliance officer, the billing vendor and two advisors, and nobody can say which of 80 open questions is still unanswered.
The Q&A module attaches each question to the document that prompted it, with permissions controlling who sees which threads, so the lender never sees regulatory counsel's questions about physician arrangements. Answers can be published to one group or to everyone, and the whole log exports for the closing file, which matters more here than in most sectors because the disclosure record is what defends the indemnity position later.
Page-level analytics show which reviewer opened which document, when, and for how long. In healthcare diligence that is an early-warning signal: a reimbursement specialist who has spent forty minutes inside the denial reports has found something, and you will usually hear about it a week before the report lands.

Per-visitor analytics show which healthcare diligence documents each reviewer opened and for how long.
After closing, data room freeze makes the room immutable and exports it as an archived ZIP with a certificate. When a billing dispute surfaces two years later, that archive is the record of exactly what was disclosed, to whom, and on what date. Set a link expiry on every reviewer link at the same time, so access to PHI-bearing folders ends on a defined date rather than persisting indefinitely.

Papermark is our #1 VDR provider for M&A transactions right now. In two deals we used custom branding, dynamic watermarking, and granular permissions.
Tyler
The Data Rooms plan is €99/month with a 7-day free trial and includes 3 team members, unlimited data rooms, unlimited documents, custom domain, dynamic watermarking, NDA agreements, and granular file-level permissions. Data Rooms Plus at €249/month adds 5 team members, the Q&A module, the visitor audit log, automatic file indexing, and SOC 2 Type II. Data Rooms Premium at €549/month adds 10 team members plus multi-team, unlimited encrypted storage, full API access, SSO on request and whitelabeling. For platform buyers running several clinic acquisitions at once, unlimited data rooms under one subscription means one room per target with no per-project fee.
No credit card required.