Compliance, benefit operations, and the evidence trail behind D-SNP supplemental benefits, written for the teams accountable for how those dollars move.
In 2025 roughly 15 percent of D-SNP members were in plans offering SSBCI. In 2026 it is roughly 90 percent. The benefit menu barely moved. What changed underneath it is the basis on which a member qualifies.
CMS increasingly expects plans to show not just that a benefit was offered, but that it was delivered, to whom, and paid for correctly.
8 min read
The monthly D-SNP compliance brief
A short, no-noise summary of CMS updates and benefit-execution practice, for compliance, operations, and actuarial teams. One email a month.
Thanks — you’re on the list. We’ll send the monthly brief.
Get in touch
Complete the form below and we'll respond within one business day.
Message received. We'll be in touch within one business day.
Legal
Privacy Policy
Effective date: January 1, 2026
Anchor Care, Inc. ("Anchor," "we," "us," or "our") operates anchorcare.ai and related services. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you visit our website or engage with our platform.
Information we collect
We may collect information you provide directly, such as your name, email address, organization, and the content of messages submitted through contact forms. We also collect certain usage data automatically, including IP addresses, browser type, pages visited, and time spent on the site, through standard web analytics tools.
How we use your information
We use the information we collect to respond to inquiries, operate and improve our services, communicate about pilot programs and product updates, and comply with applicable legal obligations. We do not sell your personal information to third parties.
Health information
Our platform is designed for use by health plans and their authorized personnel. To the extent any protected health information (PHI) is processed through our platform, it is handled in accordance with applicable HIPAA requirements and the terms of executed Business Associate Agreements.
Data retention
We retain personal information for as long as necessary to fulfill the purposes outlined in this policy, unless a longer retention period is required by law or contract.
Your rights
Depending on your jurisdiction, you may have rights to access, correct, or request deletion of your personal information. To exercise these rights, contact us through our website.
Contact
Anchor Care, Inc. · 5227 N 7th Street, Phoenix, AZ 85014
Trust & Security
Trust Center
Last updated: April 2026
Anchor is built for health plans operating in a regulated, high-stakes environment. Our security and compliance posture reflects that responsibility.
HIPAA compliance
Anchor operates as a Business Associate under HIPAA when processing protected health information on behalf of covered entities. We execute Business Associate Agreements (BAAs) with all health plan partners prior to any data exchange. Our systems are designed to support the administrative, physical, and technical safeguards required under the HIPAA Security Rule.
Data security
All data transmitted to and from Anchor's systems is encrypted in transit using TLS 1.2 or higher. Data at rest is encrypted using AES-256. Access to production systems is restricted by role-based access controls and multi-factor authentication.
Infrastructure
Anchor's infrastructure is hosted on HIPAA-eligible cloud services. We maintain audit logs of system access and regularly review access permissions. Penetration testing and vulnerability assessments are conducted on a scheduled basis.
Subprocessors
We maintain a list of subprocessors used in the delivery of our services and update it as our vendor relationships change. Health plan partners may request the current subprocessor list by contacting us directly.
Incident response
Anchor maintains a documented incident response plan. In the event of a security incident affecting health plan data, we will notify affected partners in accordance with HIPAA Breach Notification Rule requirements and any applicable contractual obligations.
Certifications & Standards
SOC 2 Type I targeted Q2 2026. SOC 2 Type II targeted Q4 2026. HITRUST r2 certification is on our 2027 roadmap. Anchor operates under HIPAA-compliant data handling practices with encryption in transit and at rest, role-based access controls, and annual third-party security review.