An NSA-compliant payment solution needs four things:
A HIPAA-compliant Good Faith Estimate process.
A pre-authorization framework for healthcare payments.
A healthcare-specific card-brand compliance
An audit trail to verify compliance when card brands or regulators require proof.
Most companies built payment processors for retail first. They added the compliance piece later, usually as a page on the website. When a patient disputes an estimate or an auditor asks for records, it creates a gap. So, address these inconsistencies early. This creates a record you can point to, and helps you avoid future errors.
Here’s what an NSA-compliant payment solution needs and how to identify vendors that follow this standard. Then, we’ll examine which healthcare payment solutions meet NSA requirements.
What NSA Compliance Means
The No Surprises Act took effect on January 1, 2022, after Congress enacted it in December 2020. It’s a key federal law that shields patients from unexpected bills. This includes out-of-network care, emergency treatment, and specialists called into in-network facilities. In these cases, patients only pay their usual in-network cost-sharing. They do not cover the difference between what the practice charged and what the plan paid.
The law also created the Good Faith Estimate requirement. Self-pay and uninsured patients need a written estimate of costs before treatment. If the final bill comes in $400 or more over that estimate, the patient can dispute it. An estimate that's late or wrong exposes a practice the same way a missing estimate does.
What This Means for Your Practice
The estimate has to go out on a strict schedule.
One business day if the visit is in three days
Three business days if it's scheduled later
It has to account for anything as an anesthesiologist or outside lab, might bill separately. And it should stay on file and be retrievable for years.
None of that is clinical work. It's a scheduling rule, a documentation rule, and a recordkeeping rule. Someone on staff must own all three for every self-pay patient.
What an NSA-compliant payment solution must include.
For a payment solution specifically, "NSA compliant" means four pieces, working together:
A documented GFE workflow: the estimate gets generated, delivered on time, and recorded, every time, not just when someone remembers.
A pre-authorization payment framework: the patient reviews and agrees to the estimate before your team charges their card.
Healthcare-specific card-brand compliance: Your payment solution follows the Visa and Mastercard rules that apply specifically to medical payments.
A full audit trail: Your system records estimates, patient authorizations, and charges so your team can show exactly what happened when needed.
How the No Surprises Act Affects Self-Pay and Uninsured Patients
Right now, Good Faith Estimates only apply to self-pay and uninsured patients. That's changing. The No Surprises Act already includes a requirement to extend GFEs to insured patients through an Advanced Explanation of Benefits. CMS/regulators have included it in the law since 2020, and industry analysis indicates that they will enact it within the next six months to a year. CMS hasn't confirmed the exact date yet.
That's not a reason to wait. Practices with a documented process in place won't notice when the rule activates. Everyone else will build it under pressure. Patients and audits are already in line.
Violations under the current GFE requirements can run up to $10,000 per violation. Once the insured-patient expansion takes effect, that exposure extends to a much larger share of a practice's patient volume.
Two case studies showed that practices giving estimates to self-pay patients are benefiting. Over half of these patients say they would pay before their visit if they know the cost. One health system even tracked a $17.8 million increase in collections at the point of service within two years of starting to provide estimates.
8 questions to ask any payment vendor
Ask these questions before signing anything. If a vendor can't answer clearly, that's the answer.
Can you show me a documented GFE workflow? A real process has steps, timing, and a paper trail. If it's a description, then it's simply marketing.
Who signs off on a Pre-Authorization Payment Form, and when? If nobody signs off before the card is charged, there's no compliant authorization step.
What happens when a patient disputes an estimate? If the answer is vague, the process behind it probably is too.
Is this built for healthcare, or adapted from a retail processor? Card-brand rules for medical payments aren't the same as the rules for a coffee shop.
Can I see your audit trail format? If a card brand or regulator asks for proof, you need to know what that proof looks like before you need it.
What's the real cost, including setup and termination? Ask for the number, not the range.
How long does onboarding take? Vague timelines usually mean undocumented processes.
Can I call a person when something goes wrong? Compliance software with no human behind it is a liability waiting to happen.
How Myriad MediPay Handles It
The best way to evaluate a payment solution is to look at the workflow itself. Here is how the Myriad Healthcare Program puts these requirements into practice.
The framework uses three documents.
Processor Agreement Rider
Pre-Authorization Payment Form
GFE Patient Option Letter
Together, these documents address the payment agreement, patient authorization, and GFE process while creating documentation for the payment workflow.
Onboarding runs three weeks through Myriad Motion. Clients who fully use the framework see big drops in aged AR. In fact, 99% report clear improvement.
What Does NSA Compliance Cost?
NSA compliance does not come with one simple price tag. The real cost depends on how many tools, vendors, and processes a practice needs to put together. Practices should consider the full range of costs involved, including transaction fees, compliance tools, administrative workflows, and documentation requirements.
1. Government and dispute fees
If a payment dispute between a practice and an insurer can't be resolved by negotiation, it moves to federal IDR arbitration. This includes a federal fee of $15 for each party in a dispute. Arbitrator fees usually range from $200 to $700 or more per dispute. The losing side pays these costs.
2. Third-party compliance and repricing platforms.
Larger health plans and health systems often hire specialized vendors for this layer. These vendors usually do not charge a flat rate. Most use a percentage-of-savings model. They take a cut from the savings compared to the original billed charge.
Standalone GFE and disclosure tools. For smaller practices, Good Faith Estimate tools and patient billing typically cost between $50 and $250 a month. This depends on the volume of self-pay patients. This fee is in addition to what the practice already pays for standard transaction processing.
3. Standard payment processing
Then there is the cost of actually processing the payment.
Typical fees vary by practice and payment method, but practices see:
In-person card payments: around 2.5%–2.7% plus $0.10–$0.15 per transaction
Online card payments: around 2.9% plus $0.30 per transaction
ACH payments: around 0.75%–1%, often with a cap near $5
Gateway fees: $0–$35 or more per month
4. Hidden Costs of NSA Compliance: Managing Multiple Payment and Compliance Systems
A practice may use one system to process payments, another to manage GFEs, and another vendor for compliance or repricing. Each system can introduce its own fees, workflows, logins, and documentation requirements.
Some contracts also include setup fees or termination penalties that do not become obvious until a practice reviews the agreement closely.
The result is more than a higher bill. Staff have to manage multiple processes and make sure the right documentation follows each one.
How NSA Compliance Affects Healthcare Payment Workflows
There's a practical detail to consider: GFE requirements for uninsured patients are now active. However, the Advanced EOB requirement for insured patients is still waiting for final rules.
This creates a two-tiered system that confuses both staff and patients. Documentation is where many practices struggle the most. Both patient consent for out-of-network care and GFE records need to hold up if someone reviews a case.
The question, then, changes from "How much does payment processing cost?"
to "How much does it cost to build and maintain a payment process that supports compliance?"
NSA-Compliant Payment Processing in One System
If you're curious about how Myriad MediPay handles all this, let's walk through it step by step. The answers to most of your pricing questions are simpler than you expect.
There is no setup fee to get started. There is no termination fee if a practice decides to leave (if within the Good Faith Guarantee). And there is no separate software invoice for a standalone GFE tool. It's one system, priced as one thing. And that leads to an important distinction. The difference is between a vendor being "compliant" and your practice having a payment process that consistently supports compliance. The first is a statement. The second is something you can demonstrate.
That is why the 8 questions above matter. A strong payment solution should be able to show you how it handles GFEs, patient authorization, and audit documentation as part of the normal workflow.
The Myriad Healthcare Program was designed around that principle. It connects the GFE, authorization, payment, and documentation process in one healthcare-specific framework.
Ask the questions. See the workflow. Then decide if your payment process is ready. Talk to a compliance consultant, or request to see the full Healthcare Program.
What Healthcare Payment Support Should Look Like
Compliance is only one part of the payment experience. Practices also need a team they can reach when questions come up.
Take a look at what our clients say about working with a payment team that is available when they need it:
“I have never had a payment company you can actually call and talk to a human being.”— Vicki Houghton
The right payment partner should provide both the technology and the support your team needs to use it.
Frequently Asked Questions
What are some healthcare payment solution options for NSA compliance?
Options vary from standalone GFE and disclosure tools ($50–$250/month) to full payment platforms with built-in compliance, such as Myriad MediPay. The difference is in the location of the GFE workflow, pre-authorization, and audit trail. They can either be part of the system or added separately.
Is NSA compliance mandatory for all practices?
Yes, though what applies varies by practice. Certain baseline provisions apply to every licensed practice regardless of size: patient disclosure notices and specific billing rules. Other requirements, including the Good Faith Estimate process, depend on patient insurance status and service setting. HHS and CMS have been clear that compliance with the rules that do apply isn't optional.
What happens if a practice isn't NSA compliant?
The costs go beyond a single fine. HHS can fine up to $10,000 for each violation. CMS has already penalized non-compliant hospitals for price transparency. Fines range from about $32,000 to over $300,000 per organization. Source: MD Clarity Under the Hospital Price Transparency Rule, CMS lists every penalized organization on its enforcement page. A late or inaccurate estimate brings reputational risks, along with financial ones, especially if it leads to public enforcement listings.






