Felix signed a payer contract renewal eighteen months ago that read clean on every page his legal team flagged. Nine months in, the payer used a retroactive denial provision buried in the claims administration section to pull back reimbursement on a batch of claims going back fourteen months. Nobody on Felix's side had negotiated a shorter lookback period, because nobody had specifically checked for one. The clause wasn't hidden. It just wasn't on anyone's list of things to check.

Felix's team didn't lose that money because they negotiated poorly. They lost it because a 100-page contract has more places to hide risk than any one reviewer can hold in their head without a checklist telling them where to look.

Payer contracts get reviewed by smart people, and risky provisions still make it through, because most contract review happens clause by clause without a structured list of the specific provisions known to cause problems. A reviewer can read every page carefully and still miss a retroactive denial window, an overbroad audit right, or a downcoding provision, because none of those individually look alarming without knowing what to compare them against.

The external problem is real: healthcare contracts are dense, and payers have every incentive to write ambiguity into the clauses that benefit them most. But the internal problem is what actually causes the loss. It's reviewing a contract without a specific list of known risk points to check it against, the way Felix's team did. General diligence catches general problems. It doesn't reliably catch the twentieth provision on a list nobody was using.

I've built my own checklist of preferred contract provisions over years of doing this work, because the alternative is relearning the same lesson every time a new risk surfaces in a signed agreement.

The 20 provisions worth checking on every, single contract

  1. Fee schedule changes — make sure the contract prevents unilateral, material rate changes without notice.

  2. Retroactive denials — limit how far back a payer can reach to deny a paid claim, based on what your organization can tolerate.

  3. Out-of-network penalties — address penalties for out-of-network services directly, including anything touching EMTALA-covered care.

  4. Administrative fees — check for hidden costs tied to claims processing. Rare, but worth confirming they're absent.

  5. Auditing rights — limit how broad a payer's medical record audit rights are, and cap the lookback period.

  6. Prior authorization requirements — clarify vague or overly restrictive language, and use any gold-card programs available to you.

  7. Term and termination — push for mutual notice periods, longer ones where the relationship supports it, and check whether statute already dictates timelines for governmental payers.

  8. Dispute resolution — confirm the process is clear and unbiased, and understand which forms of resolution, informal through litigation, you're agreeing to accept.

  9. Downcoding — prevent unjustified downcoding of services, particularly around emergency care and MS-DRG assignments. Loop in coding leadership to review this language specifically.

  10. Bundling — watch for overly broad service bundling that quietly reduces reimbursement.

  11. Exclusivity clauses — rare outside narrow network or ACO arrangements, but confirm nothing restricts your ability to contract elsewhere.

  12. Payment timelines — check reimbursement timelines against state and federal requirements.

  13. Data sharing — get data ownership and sharing terms explicit, with input from your data security team or CIO.

  14. Referral restrictions — reasonable for some coverage types, but confirm access to your own primary care providers isn't cut off.

  15. Indemnification clauses — avoid indemnification terms that put unreasonable burden on your organization. Legal review here is non-negotiable.

  16. Credentialing delays — push for timely credentialing language, since delays here translate directly into delayed revenue.

  17. Coverage determinations — make sure medical necessity language is clear, using state or federal definitions where they exist.

  18. Late payment penalties — build in real penalties and interest for payer payment delays, to the extent the law allows.

  19. Technology requirements — don't accept technology mandates without your IT team's review and sign-off, and confirm training is included.

  20. Network adequacy provisions — avoid vague adequacy language, and confirm every provider you need is actually participating before you sign.

That's a checklist, not a formality. Every one of these has cost a provider organization real money somewhere, usually because it wasn't checked on the way through.

What changes when the list gets used

Skip this kind of structured review, and a contract that looks clean can still cost you fourteen months of reimbursement on a clause nobody thought to check, the way Felix's did.

Felix's team built their own version of this checklist after that retroactive denial and started running every new contract against it before signature. On the next renewal, the retroactive denial window came back on their checklist immediately, they negotiated it down to six months, and the coding team caught a downcoding provision in the same review that would have cost them on emergency claims. Both got fixed in redlines instead of in a claims recovery effort a year later.

Print this list of twenty and run it against the next contract that crosses your desk, line by line, before it goes to signature.

A contract that reads clean isn't the same as a contract that's safe. The difference is whether someone checked it against the specific risks known to hide in this kind of agreement.

Call to Action: If one of these twenty provisions has ever cost your organization money after signature, tell me which one in the comments. I want to hear which ones are catching people most right now.

Send this to whoever reviews contracts on your team before the next one lands on their desk.

About the Author: Kevin W. Barron, MBA, FHFMA, FACHE is a nationally recognized healthcare contracting and payer relations executive with over 30 years of experience in healthcare finance. He is an author, speaker, and mentor to emerging leaders in healthcare finance. Follow Kevin on LinkedIn or subscribe to his weekly newsletter at https://www.KevinWatsonBarron.com

Disclaimer: This article is provided for general informational and educational purposes only. It reflects my personal views and observations based on professional experience in healthcare finance, managed care, payer relations, and revenue cycle operations. It should not be interpreted as legal, financial, regulatory, actuarial, or reimbursement advice. The content is not intended to represent the official position of my employer, any payer, provider, professional association, or other organization with which I may be affiliated. Readers should consult their own legal, financial, compliance, actuarial, or operational advisors before making decisions based on the issues discussed. Any references to payers, providers, regulations, market trends, or reimbursement practices are intended for discussion and education only and should not be construed as a statement about any specific contract, negotiation, patient matter, or confidential business arrangement.