Vermont’s new clinical decision-making law isn’t an isolated event. It’s the latest entry in a wave of state legislation — from California and Oregon to Massachusetts, Connecticut, Maine, Pennsylvania, and North Carolina — that has reshaped the compliance landscape for MSO/PC arrangements, telehealth platforms, and their private equity sponsors since 2025. Understanding Vermont on its own is useful. Understanding where it sits in the broader pattern is more useful still, because the pattern is what determines where this is all headed next.
Vermont’s approach, briefly
Effective July 1, 2026, Vermont’s Act 133 (H.583), codified at 18 V.S.A. chapter 233, does two things at once: it imposes substantive limits on private equity and hedge fund control over clinical operations, and it creates a new ownership-transparency regime run through the Green Mountain Care Board.
The control restrictions split into two tiers. The first bars interference with provider judgment on diagnostics, referrals, care plans, and scheduling. The second — more operationally significant — bars a PE group or hedge fund from exercising or holding delegated authority over eight categories of facility operation, including clinical staffing, medical records, payer-contracting terms, pricing, and billing decisions. The restriction reaches beyond direct ownership to any controlled entity and any arrangement that would enable the prohibited conduct, meaning compliance review has to run through management agreement mechanics, not just cap tables.
The MSO carve-out survives, but only where a licensed provider retains ultimate responsibility and approval authority, and the arrangement doesn’t amount to de facto control over operations affecting clinical decision-making or care quality. That second condition is a functional test, not a documentary one — it looks at how an arrangement actually operates, not how it’s captioned.
On the transparency side, facilities and MSOs with PE or hedge fund ownership must disclose ownership identities, org charts, and financials to the state by March 2027, most of which becomes public record. Telehealth-only entities are exempt from that reporting obligation — but not from the underlying control restrictions, which apply to any health care facility doing business in the state regardless of delivery channel. That asymmetry is easy to miss and matters most for telehealth operators evaluating their Vermont exposure.
The broader pattern Vermont fits into
Vermont’s structure only makes sense against what other states have already done. Several trends are visible across the states that have acted since 2025:
Two regulatory tools are increasingly bundled together. States are combining transaction-notice regimes — pre-close filings to an attorney general or health authority — with substantive CPOM-style restrictions on operational control. A growing number of states, Vermont included, now do both in a single statute rather than choosing one approach.
California and Oregon remain the two hardest compliance priorities, but they diverge in method. Both took effect for new arrangements as of January 1, 2026. California’s approach is enforcement-and-prohibition focused: it bars investor interference with physician and dentist professional judgment and goes further than prior guidance by prohibiting contract terms that restrict a departing provider’s competition or chill provider speech about care quality, utilization, or revenue practices, with the attorney general empowered to pursue equitable remedies. Oregon went further structurally — it prohibits PE-controlled MSOs from exercising de facto control over clinical decisions, staffing, billing policy, and payer negotiations, and unlike most other states, it also restricts the ownership and governance overlap between the MSO and the professional entity directly, not just conduct.
“De facto control” is becoming the operative legal standard. Oregon, Vermont, and California all now rely on some version of a functional-control test rather than formal ownership alone. This is the most important shift at the drafting level: a management agreement that formally reserves final approval to the professional entity, but routes budget authority, staffing ratios, or vendor selection through the MSO, is precisely the structure these statutes are built to reach — regardless of how the agreement is worded.
Enforcement has moved from theoretical to active, and three recent California matters show exactly where regulators are looking. In a pending appellate case, the California Attorney General filed an amicus brief arguing that an MSO’s unilateral right to replace a professional entity’s physician-owner violates the corporate practice doctrine even if that right is never exercised — the reserved authority itself is the problem, because it makes the physician’s ownership nominal. Separately, the AG reached a $4.5 million settlement over an MSO arrangement in which the MSO held complete authority over advertising, payor negotiations, and equipment selection; required the professional entities to finance exclusively through the MSO at above-market rates secured by a lien on their own assets; and used assignable option agreements that let the MSO control who succeeded as the physician-owner. In a third matter, a dental MSO was permanently enjoined from owning practice property, hiring or evaluating clinical staff, setting compensation, directing scheduling, and using revenue-based fees, and paid $2 million in penalties, $300,000 in restitution, and agreed to a 36-month compliance monitor. Read together, the throughline is that regulators are looking past labels to whether a lay entity holds practical control — and control that’s reserved but unused counts just as much as control that’s actively exercised. Enforcement figures and penalty amounts referenced above are drawn from publicly available state attorney general announcements, settlement materials, and related court or agency filings.
In Oregon, a hospital operator separately canceled a staffing arrangement after a federal judge raised sharp doubts about whether the arrangement complied with the state’s corporate practice of medicine restrictions. The assumption that an arrangement is safe simply because it hasn’t been challenged before no longer holds in these states.
Enforcement of the underlying doctrine isn’t limited to states passing new statutes. North Carolina has no new CPOM legislation, but its medical board is actively enforcing the existing doctrine, reportedly handling multiple corporate-practice cases a year. Its guidance treats certain MSA terms as direct evidence of a “straw ownership” problem — particularly provisions restricting a professional entity’s own control over its medical records or bank accounts, or restricting a physician-owner’s ability to sell the practice. That’s a useful reminder that CPOM risk isn’t only a new-legislation story; it’s also an active-enforcement story in states that have had a doctrine on the books for years.
Real estate and sale-leaseback structures are the newest enforcement frontier. Connecticut has repeatedly introduced legislation restricting REIT ownership of health care real estate, following Massachusetts’s move to increase scrutiny of REIT arrangements. Pennsylvania’s proposed legislation would go further downstream, treating sale-leasebacks as a risk category and empowering the state to block acquisitions that could disrupt continuity of care. This is a distinct compliance axis from clinical-control restrictions — it targets deal and real estate structure rather than clinical operations — and it’s worth tracking separately from CPOM developments.
Private rights of action are starting to appear. Vermont gives aggrieved providers a direct cause of action against a violating PE group or hedge fund for equitable relief, damages, costs, and fees. Where adopted, this changes the risk calculus meaningfully — exposure no longer depends solely on regulator enforcement priorities, but opens the door to provider-initiated litigation as well.
The definition of who’s covered keeps expanding. Nearly every new statute broadens the regulated universe beyond “the PE fund that owns the entity” to include significant equity investors and controlling lessors or operators of facility property, independent of direct equity ownership. For layered fund structures, this means compliance review increasingly has to trace every tier of the ownership stack, not just the top-line sponsor.
What this means going forward
Two things are true at once. First, this is a genuine tightening cycle — driven substantially by concern over high-profile health system failures — with more than a dozen states advancing CPOM or MSO-related bills over the past two legislative sessions. Second, the trend is not uniform, and the record backs that up: a North Carolina bill that would have barred physician-owners from holding interests in their own MSO alongside non-physician investors failed to pass in June 2026, and comparable restrictive proposals also failed in Maine, Minnesota, New Hampshire, and Washington over the same period. Failed bills aren’t nothing, though — their introduction signals growing legislative appetite in those states even where the votes weren’t there yet, which is worth watching heading into the next session.
Either way, a few practical takeaways hold across the states we’ve reviewed:
- A telehealth reporting exemption in one state says nothing about whether that state’s underlying control restrictions apply — the two need to be checked independently, and Vermont is unlikely to be the last state to build in that asymmetry.
- The functional “de facto control” test, not the formal ownership structure, is becoming the dominant compliance risk. Agreements drafted years ago to satisfy a traditional ownership-based CPOM analysis may not hold up if actual operating practice — budget authority, staffing decisions, fee-setting — functionally sits with the MSO.
- Multi-tier ownership and lease/operating arrangements increasingly carry their own exposure, independent of equity percentages, as more states adopt broad “significant equity investor” and controlling-operator definitions.
- Management fee structure is no longer a drafting afterthought. Revenue-based MSA fees are increasingly read by regulators as evidence that the MSO has a financial stake in clinical volume or billing decisions — exactly the kind of incentive the CPOM doctrine is meant to prevent. A cost-plus or flat-fee model, or some mixture of the two, is the more defensible structure, and it’s the only fee approach we recommend to clients regardless of which state’s version of these restrictions applies.
For MSOs, telehealth platforms, and their investors operating across multiple states, the practical challenge is no longer any single state’s statute — it’s reconciling a growing number of different formulations of “control,” “de facto authority,” and “covered investor” against one operating structure. That reconciliation is where most compliance risk now lives, and it’s where early legal review tends to pay for itself many times over.
Why LumaLex
This is exactly the kind of problem LumaLex was built around. We’re a boutique firm, but our practice is deliberately concentrated at the intersection of transactional structuring and regulatory fluency in telehealth and corporate-practice-of-medicine work — which means we’re not translating a generalist’s read of a new statute after the fact. We’re tracking these bills as they move through committee, comparing them against the CPOM, MSO, and telehealth licensure frameworks already in place across all 50 states, and building that comparison into the actual governance documents, management agreements, and entity structures our clients operate under.
That combination matters here specifically because the compliance risk in this space rarely lives in a single clause. It lives in how a management fee is calculated, how a staffing decision actually gets made, which entity holds approval authority on paper versus in practice, and how all of that reads once regulators start applying a functional “de facto control” test instead of a formal ownership test. Reviewing an MSO agreement for CPOM compliance in isolation, without asking how it would perform under Oregon’s or Vermont’s control standard, or how a real estate or lease arrangement might independently trigger reporting obligations, only catches part of the exposure.
Whether you’re standing up a new MSO/PC structure, expanding an existing telehealth platform into additional states, or auditing legacy agreements against this fast-moving regulatory landscape, LumaLex can help you see the whole board — not just the state you’re asking about, but how that state’s approach interacts with everywhere else you already operate.
This post is provided for general informational purposes and does not constitute legal advice. If you have questions about how these developments affect your telehealth platform, MSO structure, or multi-state investment strategy, please contact the LumaLex Law team.
Disclaimer: This article is provided for general informational purposes only and does not constitute legal advice or create an attorney-client relationship. Health, Licenses, and Cannabis rules vary by state and change frequently. Consult qualified counsel about your specific facts.



