Skip to main content
v2026.11,610 entries · CC-BY 4.0
LAC HealthLaboratory & ResearchLab & research supplies.Reagents, consumables, PPE & instruments — documented, fast, chain-of-custody shipping.Shop lac.us lac.us

GPO Safe Harbor: The Anti-Kickback Exemption for Group Purchasing Organizations

The GPO safe harbor at 42 CFR 1001.952(j) exempts group purchasing organization administrative fees from the Anti-Kickback Statute when a written member agreement and annual fee disclosure requirement are both met.

Ask about GPO Safe Harbor: The Anti-Kickback Exemption for Group Purchasing Organizations

Answers are drawn from this guide and the rest of the CASRAI corpus, with a link to every source.

Answers are AI-generated from CASRAI’s own published pages and can be wrong, so check the linked sources before relying on one; your question is logged without personal data — never sold, never used to train a third-party model — to show us what CASRAI is missing, so please do not type personal or confidential details. How we use this

The “GPO safe harbor” is the regulatory exemption at 42 CFR 1001.952(j) that allows a group purchasing organization (GPO) to collect an administrative fee from vendors on purchases made by its member hospitals, labs, and health systems without that fee being treated as an illegal kickback under the federal Anti-Kickback Statute (AKS, 42 U.S.C. 1320a-7b(b)). It is one of the original safe harbors issued by the HHS Office of Inspector General (OIG) alongside the broader 1991 safe harbor rulemaking, and it remains the framework procurement and compliance staff use today to structure, negotiate, and audit GPO participation agreements.

Why a Safe Harbor Is Needed at All

The Anti-Kickback Statute makes it a criminal offense to knowingly and willfully offer, pay, solicit, or receive any remuneration to induce referrals or purchases of items or services reimbursable under a federal health care program (Medicare, Medicaid, and others). Read literally, that sweeps in an enormous amount of ordinary commercial activity. A GPO’s core business model — negotiating volume discounts with vendors on behalf of member hospitals and labs, then funding its own operations by taking a percentage-based administrative fee out of those vendor sales — involves exactly the kind of vendor-to-purchaser-intermediary payment the statute is written broadly enough to capture, even though it is a legitimate and, for most health systems, essential purchasing mechanism.

Congress addressed this in the Medicare and Medicaid Patient and Program Protection Act of 1987, which directed OIG to define specific “safe harbor” arrangements that, if fully satisfied, are not treated as prohibited remuneration under the AKS. The GPO safe harbor is the provision that covers this arrangement specifically. Falling outside a safe harbor is not automatically illegal — arrangements are still evaluated under the statute’s intent-based standard — but safe harbor compliance removes AKS risk from the arrangement entirely, which is why GPOs and their vendor and member contracts are routinely drafted to fit inside it rather than relying on a case-by-case intent defense.

The Two Requirements Under 42 CFR 1001.952(j)

The safe harbor protects a payment a vendor makes to a GPO in connection with a purchase by one of the GPO’s members, provided both of the following conditions are met.

1. A written agreement with each participating member

The GPO must have a written agreement with each individual or entity for which it purchases goods or services (its member hospitals, labs, and health systems). That agreement must either:

  • state that participating vendors from which the member purchases will pay the GPO a fee of 3 percent or less of the purchase price of the goods or services provided by that vendor, or
  • if the fee is not fixed at 3 percent or less, specify the amount the GPO will be paid by each vendor, or, if that amount is not known at the time the agreement is executed, specify the maximum amount the GPO could receive from each vendor.

2. Annual written disclosure of fees received

At least once a year, the GPO must give each member for which it purchases goods or services written notice of the amount received from each vendor with respect to purchases made by, or on behalf of, that member. The GPO must also disclose this information to the HHS Secretary upon request. This disclosure requirement exists so a member institution — and, if needed, regulators — can see exactly what a vendor relationship is costing in fees embedded in a GPO contract, rather than that cost being hidden inside a bundled purchase price.

The 3 Percent Figure, and What It Actually Controls

The 3 percent threshold is frequently misunderstood as a hard legal cap on all GPO administrative fees. It is not. It is a drafting fork in the written-agreement requirement: if the member agreement simply states that vendor fees will be 3 percent or less, the GPO does not need to specify an exact dollar or percentage figure per vendor in that agreement. If a GPO’s fee structure with a given vendor exceeds 3 percent, the arrangement can still fit inside the safe harbor — the member agreement just has to state the actual (or maximum) fee amount for that vendor instead of relying on the 3-percent shorthand. In practice, many GPO contracts are still built around the 3-percent line because it is administratively simpler, but a compliance review should not stop at “is the fee under 3 percent” — it should confirm the written-agreement language matches whichever prong the GPO’s actual fee structure requires, and confirm the annual disclosure is happening regardless of the fee level.

What Procurement and Compliance Staff Should Document

For a research institution, hospital lab, or health system participating in a GPO, a practical compliance file for this safe harbor should include:

  • The signed GPO membership/participation agreement, with the 3-percent-or-less fee statement or the vendor-specific fee disclosure language actually present in the text — not assumed or referenced verbally.
  • Copies of the GPO’s annual written fee disclosures, retained and reconciled against actual purchase volume with each vendor.
  • A record of which vendors are covered by the GPO contract versus purchased outside it, since the safe harbor only protects fees tied to purchases actually made through the GPO relationship.
  • Confirmation that any fee arrangement above 3 percent is documented with the specific or maximum amount in the written agreement, not left as an open-ended percentage.

Institutions that also participate in cooperative purchasing under federal grant terms should not conflate this AKS safe harbor with the separate cost-allowability rules for cooperative and intergovernmental purchasing arrangements under 2 CFR 200.318(e) — the two govern different questions (fraud-and-abuse exposure versus federal award cost allowability) and a GPO contract that is clean under one is not automatically clean under the other.

How This Relates to Other AKS Safe Harbors

The GPO safe harbor sits alongside several other AKS safe harbors that procurement and research-compliance staff commonly encounter, and it is worth keeping the boundaries clear:

  • Discounts safe harbor (42 CFR 1001.952(h)) protects properly disclosed and appropriately reflected discounts a seller gives directly to a buyer. The GPO safe harbor is a distinct provision because a GPO is an intermediary receiving a fee, not a buyer receiving a discount, even though the practical effect (lower net cost to the member) can look similar.
  • Personal services and management contracts safe harbor (42 CFR 1001.952(d)) covers a different category of arrangement — compensation for services rendered, such as consulting or management functions — and requires a signed writing, a term of at least a year, and fair-market-value compensation set in advance without regard to referral volume. It is not a substitute for GPO fee compliance if a GPO arrangement also includes separate consulting or services payments.

Vendors selling into research institutions through a GPO contract should also be aware that GPO/manufacturer relationships intersect with separate transparency obligations, including reporting under the Physician Payments Sunshine Act and CMS Open Payments program, which separately requires “applicable group purchasing organizations” to report certain payments and ownership interests involving physicians. Satisfying the AKS safe harbor does not by itself satisfy Sunshine Act reporting obligations — they are separate regulatory regimes.

Frequently Asked Questions

What are the GPO safe harbor requirements?

Two requirements must both be met: a written agreement between the GPO and each participating member either capping vendor fees at 3 percent or specifying the actual/maximum fee amount per vendor, and at least annual written disclosure by the GPO to each member (and to HHS on request) of the fees it actually received from vendors on that member’s purchases.

Is a GPO administrative fee illegal if it’s over 3 percent?

Not automatically. A fee above 3 percent can still fit inside the safe harbor if the written member agreement specifies the actual or maximum fee amount for that vendor rather than relying on the “3 percent or less” language. The disclosure requirement applies regardless of the fee level.

Who is responsible for meeting the GPO safe harbor’s requirements — the GPO or the member institution?

The written-agreement and disclosure obligations fall on the GPO. As a practical compliance matter, however, member institutions (hospitals, labs, research institutions) should independently confirm the agreement contains the required fee language and that annual disclosures are actually being received and reconciled, rather than assuming the GPO’s paperwork is complete.

Does the GPO safe harbor cover research institutions and university labs, or only hospitals?

The safe harbor is not limited to hospitals. It applies to any individual or entity for which a GPO purchases goods or services under a qualifying written agreement, which includes university-affiliated labs, health systems, and other research institutions that purchase supplies, reagents, or equipment through a GPO contract.

This page summarizes the regulatory framework at 42 CFR 1001.952(j) for procurement and compliance staff evaluating or auditing GPO agreements. It is not legal advice; institutions should confirm current agreement language with counsel or their compliance office, particularly for fee structures that do not fit cleanly within the 3-percent prong.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →