Regulatory Landscape Shifts in Medical Governance

Navigating the 2024 Healthcare Compliance Legislative Review
Healthcare compliance legislative review

Keeping up with shifting legal requirements in healthcare can feel overwhelming. A Healthcare compliance legislative review systematically examines your organization’s policies against current laws to identify gaps and reduce risk. It provides a clear roadmap for meeting legal obligations, helping you protect patients and your practice with confidence.

Regulatory Landscape Shifts in Medical Governance

The rhythm of the legislative review disrupted our quarterly compliance meeting. A shift in medical governance was palpable, not from a new law, but from an emerging interpretive framework. Our legal team, accustomed to static checklists, now parsed ambiguous language about shared decision-making protocols. The real context: a hospital board had to recalibrate its peer review process overnight, aligning with a governance shift that redefined physician autonomy within compliance structures. What defines a regulatory landscape shift in medical governance? It is when the unwritten rules governing physician accountability become the primary subject of a legislative review, forcing compliance to interpret intent, not just text.

Healthcare compliance legislative review

Recent Federal Statutes Reshaping Provider Obligations

Recent federal statutes, particularly the No Surprises Act and information blocking rules, directly reshape provider obligations by mandating new patient cost estimates and data-sharing protocols. These laws require providers to offer good-faith estimates before scheduled care and to avoid knowingly interfering with electronic health information access. Compliance now demands updated billing workflows and technical interoperability investments. The starkest shift is the legal risk for non-compliance, as providers face penalties for failing to meet these specific patient-facing transparency duties.

Q: How do recent federal statutes alter provider obligations for patient data?
A: They compel providers to proactively share electronic health information with patients and other systems, barring practices like blocking data access, under threat of civil monetary penalties.

State-Level Legislative Trends Affecting Compliance Protocols

State-level legislative trends now compel compliance protocols to adapt to non-uniform mandates, requiring frameworks that track disparate jurisdiction-specific requirements. For instance, telemedicine consent standards and data breach notification timelines vary widely, forcing compliance officers to configure protocols with multi-state modular logic. This fragmentation demands dynamic auditing systems rather than static checklists. Q: How do compliance protocols manage conflicting state rules? A: By implementing tiered approval workflows and state-specific policy overlays within the core system, ensuring adherence without disrupting operational flow.

Intersection of Public Health Emergencies and Rulemaking

Public health emergencies compel agencies to bypass standard notice-and-comment periods, forcing compliance teams to track emergency interim final rules that take effect immediately. This creates a dual-track compliance burden: adhering to temporary measures while preparing for potential permanent codification post-crisis. The intersection requires monitoring executive orders and HHS secretarial determinations, as these trigger statutory waiver authorities that can suspend existing compliance obligations. Analytical scrutiny of sunset clauses is critical, as premature expiration of emergency rulemaking can create gaps in operational continuity. Practical response protocols must differentiate between rules tied to the declared emergency and those instituting lasting regulatory shifts.

Key Enforcement Priorities Under Updated Legal Frameworks

In a healthcare compliance legislative review, the key enforcement priorities under updated legal frameworks center on heightened scrutiny of data privacy breach notifications and the accurate attribution of telehealth services. Practitioners must verify that all remote encounters are documented with precise location and provider identification, as regulators now treat discrepancies as presumptive fraud.

A single mismatched code between a telehealth visit and its supporting record can trigger a full retrospective audit of your entire service line.

Additionally, enforcement now aggressively targets non-compliance with real-time reporting of adverse device events, shifting from periodic summaries to immediate, granular submissions. Your review should prioritize these two control points—data integrity in virtual care and instantaneous adverse event reporting—since auditors have publicly stated they will issue immediate civil monetary penalties for first-time omissions without corrective action plans.

Healthcare compliance legislative review

Office of Inspector General’s Focus Areas in the Current Cycle

In the current cycle, the Office of Inspector General is zeroing in on telehealth and remote monitoring compliance, making sure providers don’t bill for services that never happened. They’re also digging into value-based care arrangement risks, especially around improper patient referrals or upcoding in shared savings models. Their focus areas include auditing prior authorization practices and checking for data manipulation in electronic health records. Here’s a quick look at what they’re watching:

  • Telehealth fraud: verifying live interactions and proper documentation.
  • Kickback detection: reviewing financial ties between providers and referral sources.
  • Managed care oversight: ensuring accurate risk adjustment reporting.

False Claims Act Revisions and Liability Risks

Recent False Claims Act revisions have sharpened liability risks for healthcare providers by lowering the bar for intent. Even billing errors from unclear coding guidance can now trigger penalties if the government argues «reckless disregard.» The updated framework also expands whistleblower protections, making internal audits even more critical. Q: How do these revisions increase my daily liability? A: They mean a simple failure to double-check a compliance update could be framed as conscious avoidance, shifting the burden onto you to prove you weren’t deliberately ignoring red flags.

Anti-Kickback Statute and Stark Law Modifications

Updated enforcement priorities hinge on modifications to the Anti-Kickback Statute and Stark Law safe harbors. Compliance programs must now scrutinize value-based arrangements more rigorously, as new exceptions permit certain remuneration if structured around patient outcome benchmarks. Organizations should audit all referral relationships to ensure they meet the updated, outcome-driven criteria. Avoid assuming legacy arrangements are compliant; proactive restructuring is essential to mitigate liability risk under these tightened frameworks.

  • Review all compensation arrangements against new value-based safe harbor exceptions.
  • Ensure any in-kind remuneration tied to referrals is documented with outcome metrics.
  • Validate that space or equipment rentals adhere to revised fair market value guidelines.
  • Integrate Stark Law self-referral prohibitions into annual compliance training modules.

Impact of Privacy and Data Security Mandates

The mandate for ironclad patient data security reshapes every step of a compliance legislative review. During a recent audit, our team uncovered that a single unencrypted email thread between a specialist and a lab violated the new privacy standards, forcing us to rewrite our entire data handling protocol. This real-world pressure means we scrutinize each legislative clause not as abstract law, but as a direct instruction for how we lock down records and train staff. The review process itself now begins with a map of where patient data lives, because a mandate can only protect what we first admit is vulnerable. Every policy update we draft is now measured against the simplest test: does this shield a person’s health history from a breach?

HIPAA Updates and Digital Health Record Requirements

HIPAA updates now mandate that digital health records include granular patient access logs, requiring providers to offer electronic copies in under 30 days. Compliance demands a revised patient consent framework for data sharing across authorized platforms. For digital record requirements, a clear sequence must be followed:

  1. Audit current systems to confirm encrypted storage and transmission of ePHI.
  2. Implement audit trails that track every access, modification, and disclosure of digital records.
  3. Update patient-facing portals to support immediate revocation of data-sharing permissions.

State Privacy Conflicts and Patient Consent Standards

State-level privacy laws create conflicting patient consent standards for healthcare providers operating across multiple jurisdictions. A patient’s consent obtained under California’s stricter opt-in requirements may not satisfy a less restrictive state’s data-sharing exceptions, forcing providers to apply the highest standard to all records. This fragmentation complicates consent workflows, as a single record might be subject to conflicting rules on re-disclosure, revocation, or secondary use. Providers must map each patient’s state of residence against the applicable consent thresholds for treatment, payment, and operations to avoid non-compliance.

Q: How should a provider handle conflicting consent standards between a patient’s home state and the provider’s state?
A: Apply the most restrictive patient-consent requirement from either jurisdiction to that specific data-sharing activity, ensuring the patient’s explicit authorization outweighs the permissive standards of the less restrictive state.

Breach Notification Timelines Post-2024 Legislation

Post-2024 legislation compresses breach notification timelines, demanding immediate action from healthcare entities. You must now report most breaches within 72 hours of discovery—not confirmation—shifting the burden to proactive incident detection. This means accelerated breach response workflows become critical. To comply, follow this sequence:

  1. Deploy real-time monitoring tools to catch data exposure instantly.
  2. Activate a pre-approved notification template within hours of detection.
  3. Submit the preliminary report to regulators before full forensic analysis concludes.

Delay is no longer viable; your system must trigger alerts before you finish verifying the breach scope.

Telehealth and Remote Care Regulatory Adjustments

Navigating Telehealth and Remote Care Regulatory Adjustments within a healthcare compliance legislative review demands a proactive recalibration of how providers verify patient identity and secure digital consent. Compliance now hinges on updating privacy protocols to match revised interstate practice allowances, ensuring your platform’s data encryption aligns with shifting confidentiality mandates. You must adapt audit trails to capture location-based validation and session integrity, as legislative reviews often tighten oversight of remote prescribing and virtual care documentation. Every adjustment you make to telehealth workflows should directly counter compliance gaps flagged by recent legislative scrutiny, turning regulatory shifts into practical safeguards for both practice integrity and patient trust.

Cross-State Licensing Flexibilities and Sunset Dates

When looking at healthcare compliance, cross-state licensing flexibilities often come with a built-in timer. These temporary allowances, like waivers for out-of-state providers, usually have specific sunset dates baked in. Practically, this means you need to check the expiration date on any flexibility you rely on. If you’re using a waiver to see patients across state lines, mark that sunset date on your calendar. The sequence is simple:

  1. Identify which licensing flexibility applies to your current setup.
  2. Find the exact sunset date for that flexibility in your state’s laws.
  3. Create a plan to transition before that date hits, or advocate for an extension if needed.

Staying ahead of these sunset date compliance prevents a sudden loss of service ability for your remote patients.

Medicare and Medicaid Coverage Rule Changes

Medicare and Medicaid coverage rule changes demand immediate attention in any healthcare compliance legislative review, as they redefine which telehealth services qualify for reimbursement. Providers must adapt to new codes that now cover remote patient monitoring for chronic conditions, while temporary waivers for audio-only visits have been made permanent. Failure to align billing practices with these updates risks audit penalties. Medicare and Medicaid coverage rule changes also expand originating site flexibility, allowing patients to receive care from home without geographic restrictions. Every claim must now document a legitimate provider-patient relationship established via real-time, interactive communication.

Medicare and Medicaid coverage rule changes now mandate strict compliance with expanded telehealth codes, permanent audio-only allowances, and home-based originating site reforms to secure reimbursement.

Remote Monitoring Compliance and Reimbursement Criteria

For effective remote monitoring compliance and reimbursement, providers must verify that each device and data-collection protocol meets stringent documentation standards. Reimbursement hinges on proving that transmitted readings are reviewed by a qualified clinician within the required timeframes. You must also confirm that patients have provided explicit consent for continuous data sharing, as payers now audit for this authorization. Furthermore, session logs must clearly separate monitoring from treatment codes to satisfy billing rules. Any gap in timestamped review notes or patient acknowledgment can trigger a denial, so daily reconciliation of device logs against submitted claims is essential for maintaining compliance.

Fraud Prevention and Auditing Protocol Overhauls

A legislative review mandates a shift from retrospective fraud detection to real-time surveillance, requiring an overhaul of auditing protocols to embed proactive prevention. Your compliance framework must prioritize dynamic risk-scoring algorithms integrated directly into claims processing systems.

This means replacing manual, periodic audits with automated, transaction-level scrutiny that flags anomalies as they occur, reducing exposure before payment.

Restructure your internal audit teams to focus on pattern analysis rather than random sampling, and enforce mandatory cross-referencing of service codes against clinical documentation at the point of entry. This directly aligns your protocol overhaul with the legislative intent to halt fraudulent activity at its source, not merely penalize it after the fact.

New Self-Disclosure Incentives and Penalty Structures

The revised legislative review introduces tiered penalty mitigation as a core mechanism within new self-disclosure incentives. Entities that voluntarily report non-compliance before any investigation now qualify for a structured reduction in civil monetary penalties, often capped at a percentage of the wrongfully retained amount. Conversely, the penalty structure escalates sharply for delayed or coerced disclosures, adding a multiplier effect for each quarter of concealment. This creates a clear logical boundary: timely, complete self-disclosure yields quantifiable financial relief, while strategic silence compounds liability through mandatory disgorgement and enhanced fines, directly rewarding proactive transparency.

Claims Data Analytics and Predictive Compliance Models

For healthcare compliance, predictive compliance models let you stop fraud before money leaves the door. Analyzing historical claims data, these models spot billing patterns—like sudden spikes in high-cost procedures from a single provider—that human auditors miss. You can flag suspicious claims in real-time, not months later. Setting up a rule-based engine on top of your analytics helps catch repeat offenders faster.

  • Use decision trees to classify claim patterns as low, medium, or high risk.
  • Train models on past denied claims to improve future detection accuracy.
  • Automate alerts when a provider’s billing volume jumps outside their usual range.

Third-Party Billing Arrangements Under Scrutiny

Third-party billing arrangements under scrutiny now require providers to conduct thorough due diligence on each intermediary’s billing practices, ensuring no fraudulent codes or duplicate claims are submitted under the provider’s identifier. Audits must verify that contracts explicitly prohibit percentage-based fees tied to claim amounts, shifting to fixed, transparent compensation models. A lack of direct oversight over subcontractors hired by the billing agent can still create compliance gaps, even if the primary agreement appears sound. Providers should implement quarterly reconciliation of submitted claims against agent-reported revenue to detect unauthorized billing patterns early.

Workforce Training and Accountability Measures

In a healthcare compliance legislative review, Workforce Training must be structured around current legal interpretations to close knowledge gaps. Effective Accountability Measures ensure each team member is held to defined performance standards, directly tying training completion to operational compliance outcomes. Role-specific competency assessments are critical, verifying that training translates into correct, auditable actions at the point of care. You can confidently link employee proficiency metrics to documented compliance obligations, creating a traceable chain of responsibility that withstands legal scrutiny.

Mandatory Compliance Education Under Revised Statutes

Under revised statutes, mandatory compliance education now requires you to complete bite-sized, scenario-based modules rather than lengthy lectures. You’ll find these courses focus on daily tasks like handling patient data or reporting minor errors, with refreshers needed every six months. Your supervisor will track progress through a simple dashboard, so you can see exactly what’s due. The format is designed to fit into your shift without overtime, using real-world examples from your own department. Just log in, run through the quick quiz, and you’re set until the next update.

Whistleblower Protections and Reporting Channel Updates

Healthcare compliance legislative review

Updates to anonymous reporting channel protocols now require healthcare organizations to verify that digital and telephonic hotlines route reports directly to compliance officers without administrative bottlenecks. Practical revisions include mandating written acknowledgment of every whistleblower submission within 72 hours. Personnel must receive hands-on training to distinguish between protected patient safety disclosures and unprotected complaints, with clear instructions on securing traceable evidence. Retaliation safeguards have been tightened, requiring immediate suspension of any manager under investigation for reprisal until the review concludes.

  • Confirm reporting platforms encrypt whistleblower identities to prevent https://harvardjol.com leaks
  • Log all verbal hotline interactions with time-stamped summaries
  • Distribute step-by-step guides for submitting digital reports through secure portals

Leadership Liability for Regulatory Lapses

Leadership liability for regulatory lapses in healthcare compliance directly ties executive decisions to institutional penalties. When oversight failures occur, executives face personal accountability, including fines or exclusion from federal programs. This shifts compliance from a delegated task to a core leadership responsibility. To mitigate this, leaders must personally verify training efficacy and corrective action plans, not merely approve budgets. Executive accountability mandates that leaders proactively audit adherence gaps and enforce discipline, as passive reliance on staff invites personal legal jeopardy. Ignoring this exposes leadership to sanctions that bypass corporate protections, making direct engagement with compliance protocols a non-negotiable duty in today’s legislative landscape.

Emerging Areas in Pharmaceutical and Device Governance

The compliance officer, reviewing last quarter’s adverse event reports, now finds herself tracing algorithmic biases in a newly approved AI diagnostic tool. This is the emerging reality of pharmaceutical and device governance. Algorithmic accountability forces legislative review to scrutinize not just the device’s safety data, but the integrity of the data used to train its decision-making. Meanwhile, a field recall for a smart insulin pump revealed a software vulnerability shared across multiple manufacturers, pushing compliance frameworks to move beyond individual product liability. The shift from product-focused to system-focused governance means a compliance review must now map the entire digital ecosystem a device interacts with, including third-party data feeds and cloud storage protocols, to identify hidden risks that traditional audits would miss.

Drug Pricing Transparency Laws and Manufacturer Reporting

Drug pricing transparency laws compel manufacturers to report proprietary data, such as average sales prices and patient assistance expenditures, to state and federal agencies. A critical compliance action is verifying the accuracy of these submissions to avoid penalties under the Pharmaceutical Pricing Transparency Reporting framework. The process typically follows a sequence:

  1. Identify all products subject to reporting thresholds in each jurisdiction.
  2. Aggregate wholesale acquisition cost changes and rebate amounts per dosage unit.
  3. Submit standardized reports via state portals within statutory deadlines.
  4. Reconcile submitted data against internal pricing records to confirm consistency.

Auditors then cross-reference these filings against claims data to detect underreporting, directly impacting manufacturer rebate obligations and public formulary decisions.

Medical Device Registration and Post-Market Surveillance Edicts

Medical Device Registration and Post-Market Surveillance Edicts now demand a lifecycle compliance approach, not a one-time approval. Manufacturers must integrate **real-world performance data collection** into their initial registration dossiers. This means submitting a post-market surveillance plan alongside the technical file, detailing how adverse events and field safety corrective actions will be systematically tracked and reported. Any deviation from the submitted surveillance methodology during the product’s lifecycle triggers a mandatory update to the registration. Post-market surveillance edicts fundamentally tie market access to ongoing data validity, shifting compliance from a pre-market gate to a continuous verification loop.

Q: What triggers a mandatory registration amendment under post-market surveillance edicts?
A: Any evidence from surveillance data—such as an unexpected failure pattern or a shift in device risk classification—that contradicts the original safety assumptions in the registration file requires a formal amendment or risk a compliance breach.

Clinical Trial Conduct and Informed Consent Reforms

Reforms in clinical trial conduct are shifting toward dynamic, ongoing consent models that replace static signatures with continuous participant engagement. Investigators now prioritize comprehension checks and layered information delivery to ensure subjects genuinely understand risks and benefits. These changes mandate that sponsors embed adaptive consent processes directly into trial protocols, using digital tools to document evolving participant decisions. For compliance, this means auditing not just signed forms but the entire dialogue trail, confirming that consent remains valid through protocol modifications. Practical implementation requires retraining site staff to facilitate bidirectional communication, thereby transforming informed consent from a bureaucratic hurdle into a pillar of ethical trial governance.

Clinical trial conduct now demands continuous, documented participant dialogue rather than one-time permission, with compliance focused on verifying genuine comprehension throughout the study lifecycle.

Enforcement Trends and Historically Notable Settlements

Enforcement trends now prioritize individual accountability, with the Department of Justice aggressively pursuing executives under the False Claims Act for direct oversight failures. Historically notable settlements, such as Pfizer’s $2.3 billion resolution for off-label marketing, set the benchmark for calculating penalties based on total healthcare program revenue rather than isolated violations. Corporate integrity agreements remain the primary structural remedy, mandating independent monitors and rigorous compliance reporting post-settlement. Self-disclosure protocols have evolved into critical leverage points, reducing penalties by up to 50% when violations are proactively identified and remediated. Smart compliance teams now model settlement frameworks retroactively to preempt similar liability before enforcement triggers escalate. Recent qui tam recoveries exceeding $2.2 billion annually underscore the shift toward data-driven audits that trace billing anomalies to specific provider behavior.

Recent Corporate Integrity Agreement Patterns

Recent Corporate Integrity Agreement patterns emphasize heightened independent monitor oversight and accelerated reporting deadlines. Providers now face mandatory self-disclosure protocols tied to specific billing anomalies, with OIG requiring quarterly compliance certifications. These agreements increasingly mandate real-time claims auditing software implementation, moving beyond periodic reviews. Penalty structures now incorporate escalating financial disincentives for second-tier violations, directly linking settlement duration to corrective action completion rates. Effective compliance programs must embed these pattern-specific requirements into standard operating procedures to avoid triggering enhanced monitoring provisions.

Monetary Penalty Increases and Calculation Methods

Monetary penalties in healthcare compliance now follow a structured methodology tied to the statutory sentencing guidelines multiplier, where base fines are escalated by the number of affected individuals and the degree of organizational culpability. Calculation methods incorporate a per-violation cap adjusted annually for inflation, with CMPs (Civil Monetary Penalties) reaching up to $2,053,476 per false claim under the False Claims Act for 2024. Actual payout amounts further depend on the self-disclosure discount factor, which reduces liability by 30–50% if the entity voluntarily reports the violation. These increases are indexed to the Federal Civil Penalties Inflation Adjustment Act, ensuring automatic annual recalibration without separate legislative action.

Exclusion List Changes and Provider Reinstatement Pathways

Within the provider reinstatement pathway, exclusion list changes demand immediate operational response. When a provider lands on an OIG or state exclusion list, the healthcare entity must execute a three-step sequence: first, isolate the provider from any federal healthcare program billing or patient care; second, submit a prompt self-disclosure to the relevant agency detailing the exclusion trigger and internal safeguards; third, initiate the reinstatement request only after the exclusion period ends, which requires submitting a corrective action plan and evidence of ongoing compliance training. The reinstatement pathway is non-linear—agencies often require re-credentialing and a clean compliance audit history before lifting the exclusion. Failure to track list changes mid-cycle can derail reinstatement eligibility entirely.

  1. Isolate the excluded provider from all federal program interactions immediately upon list change detection.
  2. File a timely self-disclosure with the OIG or state Medicaid agency, outlining the exclusion event and corrective steps.
  3. After the exclusion period concludes, submit a formal reinstatement request with a compliance remediation plan and audit documentation.

Strategic Compliance Planning for Evolving Legal Terrain

Strategic Compliance Planning for Evolving Legal Terrain in healthcare requires a proactive legislative review cycle that maps regulatory signals to operational workflows. This planning involves parsing statutory language for ambiguous terms that may shift enforcement priorities, then embedding those possibilities into dynamic internal controls. A key practice is the creation of adaptive policy frameworks that can toggle between conservative and aggressive stances based on legislative revisions.

The most effective compliance plans treat legislative review as a continuous gap analysis, not a calendar-checking exercise, using trendlines from text amendments to preemptively adjust audit protocols and training modules.

By doing so, the organization avoids reactionary scrambling and maintains defensible posture regardless of how the legal terrain shifts.

Risk Assessment Frameworks Aligned with Current Legislation

Effective risk assessment frameworks must be dynamically mapped to current legislative text to remain actionable. By integrating regulatory requirements directly into the risk matrix, organizations can identify compliance gaps specific to enacted statutes rather than general best practices. This approach requires a structured process where each legal obligation is translated into a measurable risk indicator, enabling precise prioritization of remediation resources. Frameworks should include a feedback loop that automatically updates risk scores when legislation is amended, ensuring the assessment reflects the real-time legal landscape. Without this alignment, assessments risk becoming static documents that fail to address the specific liabilities defined by current law. A legislatively-aligned risk register thereby serves as the operational bridge between legal mandates and practical compliance actions.

Policy Documentation Requirements for Multi-State Operations

For multi-state operations, policy documentation must reconcile conflicting state-specific mandates into a single master framework that avoids contradictory directives. Each document requires explicit jurisdictional mapping, flagging where a state’s requirement overrides the baseline protocol. Cross-referencing state payer rules with internal operational steps is essential to prevent silent noncompliance. This demands version-controlled matrices that track interstate policy harmonization, ensuring amendments in one jurisdiction do not inadvertently breach another’s standards without a documented gap analysis. The documentation must also include time-stamped audit trails of state law comparisons to substantiate compliance decisions during reviews.

External Counsel and Compliance Officer Coordination Best Practices

Effective coordination between external counsel and compliance officers begins with a shared regulatory interpretation framework during legislative reviews. Establish a structured intake process where counsel flags ambiguous statutory language, and the compliance officer translates this into operational controls.

  1. Schedule joint baseline assessments immediately after new legislative text is published.
  2. Define a mutual confidentiality and privilege protocol to protect review work product.
  3. Create a joint escalation grid specifying when counsel must intervene on risk tolerance thresholds.
  4. Co-author a single “legislative impact memo” that aligns legal risk analysis with internal policy gaps.

This ensures both parties act on the same legal reading, preventing siloed compliance gaps or overbroad court interpretations.

What a compliance review actually covers in healthcare legislation

How the review process scans for regulatory gaps

Key legal categories that get examined during a review

How to prepare your documents before starting the review

Organizing policies, procedures, and past audit records

Checklist of required materials for a smooth review session

Step-by-step workflow of a typical legislative compliance review

Phase one: mapping current practices against statute language

Phase two: flagging discrepancies and prioritizing fixes

Top features to look for in a review tool or service

Real-time statute update tracking and cross-referencing

Automated report generation with actionable recommendations

How to interpret review results and build an action plan

Reading the risk heat map and severity scoring

Assigning corrective tasks with deadlines and ownership

Common questions users have about review frequency and scope

How often should you run a full legislative check

Can you limit the review to just federal or just state rules