340B Manufacturer Claims Data Requirements: What Hospital CFOs Must Do Before the Rules Multiply Again
Johnson & Johnson just added claims data requirements effective Sept. 15. Here is what hospital CFOs need to know before the next manufacturer follows.
Johnson & Johnson's new claims data reporting requirements for 340B covered entities took effect September 15. Hospitals now have 45 days to submit in-house pharmacy claims data after dispensing a covered J&J drug, or face suspension of 340B pricing across all J&J products.
That is not the headline. The headline is that J&J is the latest in a growing list. Bristol Myers Squibb, Eli Lilly, Novo Nordisk, AstraZeneca. Each with their own deadlines, their own scope, their own state carve-outs, their own contract pharmacy restrictions. Each one adding a separate compliance track your team has to manage independently.
This is not a documentation problem. It is a structural problem. And hospital CFOs are the ones who will pay for it while manufacturers and the government sort out whose rules actually govern.
The Financial Stakes Are Not Abstract
The 340B Drug Pricing Program generates meaningful savings for covered entities. According to 340B Health, hospitals participating in the program save an estimated 25 to 50 percent off commercial drug prices on covered drugs. For a disproportionate share hospital with significant drug spend, that translates to tens of millions of dollars annually in reduced acquisition costs. Those savings fund charity care, community health programs, and services that are otherwise uncompensated.
When Eli Lilly began enforcing its claims data policy in June and directed wholesalers to cut off 340B pricing for noncompliant hospitals, the stakes became concrete. At least one covered entity, Florida Health Sciences Center, filed suit. The litigation is ongoing.
Lilly's enforcement action is the clearest illustration of what noncompliance actually costs. It is not a penalty or a fine. It is the loss of the discount itself, on all covered products, until the covered entity demonstrates compliance. For a hospital with significant drug spend on Lilly's portfolio, that could mean paying full commercial prices on insulin, oncology drugs, and other high-cost products while the dispute is resolved.
Novo Nordisk has said similar penalties are coming for entities that have not complied with its policy. J&J's policy includes a two-notice grace period before suspension, which is more structured than some other manufacturers have offered. But the direction of travel is clear.
If you worked through the earlier enforcement cycle this spring, the strategic framing in my piece on the CFO's 90-day action plan for 340B stability still holds as context for where the program has been heading. What has changed is the pace.
Text graphic reading: 340B Manufacturer Claims Data requirements are multiplying. Hospital CFOs need a tracking framework now, not after the next manufacturer announcement
What J&J's Policy Actually Requires
J&J's policy requires hospitals and other covered entities to submit claims data for in-house pharmacy drugs within 45 days of dispensing. Oncology and autoimmune drugs carry a 60-day deadline. Covered entities receive at least two noncompliance notices before J&J suspends 340B pricing across all products.
The contract pharmacy restriction takes effect on the same date. Discounts on J&J drugs through contract pharmacies are now limited to one pharmacy within a 40-mile radius of the covered entity.
J&J has extended these contract pharmacy restrictions to all 340B covered entities, not just disproportionate share hospitals. Federally qualified health centers, Ryan White HIV/AIDS clinics, and Indian Health Service facilities face the same constraints, with an effective date of November 3.
The American Hospital Association responded to similar policies earlier this year with a direct challenge to the manufacturer framing. Data for in-house dispenses is often spread across multiple disparate systems. Reconciling and aligning those systems creates real costs. Those costs divert dollars from patient care.
The AHA is correct. But the more important operational point is that this is now one of several manufacturer-specific policies your team has to track simultaneously.
The Cascading Compliance Problem
J&J's policy is not identical to Lilly's. Lilly's is not identical to BMS's. Novo Nordisk's is not identical to AstraZeneca's. Each manufacturer has set its own deadlines, its own scope, its own definitions of which entity types are covered, and its own state carve-outs.
Lilly exempted providers in ten states from its requirements based on current or pending state legislative protections. J&J does not appear to have made similar accommodations. The specific states, the specific drugs, the specific contract pharmacy thresholds. All of it varies by manufacturer.
A Frier Levitt analysis published before J&J announced its policy captured the problem precisely. Covered entities are now tracking a fragmented and expanding set of manufacturer-specific rules rather than a single uniform standard.
That is not a compliance team problem. That is a systems and data infrastructure problem with a direct line to your finance operations.
Early in my career at UF Health Jacksonville, a Level 1 Trauma center and Level 3 NICU with a significant safety-net patient population, I saw what happened when compliance requirements multiplied faster than the infrastructure to track them. At a facility where 340B savings were embedded in the operating model, funding charity care, uncompensated services, and community programs, a compliance gap was not an administrative problem. It showed up in the budget.
The covered entities most at risk right now are not the ones ignoring the J&J announcement. They are the ones treating each manufacturer policy as a standalone item to be addressed and checked off, without recognizing that the list will keep growing.
Comparison table of 340B manufacturer claims data reporting requirements showing different deadlines, pharmacy limits, and scope rules across five major pharmaceutical companies.
What the Government Has Not Done
HRSA has not issued a formal public response to the expanded claims data requirements.
That silence matters. HRSA administers the 340B program. Manufacturers are implementing data submission policies that function as program requirements without HRSA's formal endorsement or a uniform standard. Covered entities are caught between manufacturer enforcement actions and a federal administrator that has not clarified what is actually required.
Meanwhile, the federal policy environment is adding pressure from another direction. Beginning January 1, a separate federal requirement mandates that providers report Medicare Part D claims data to a centralized repository. That repository launches October 1 for voluntary use. Failure to comply once mandatory reporting begins could be grounds for revocation of Medicare enrollment.
The 340B rebate model is a separate debate. A federal court paused HRSA's rebate model pilot in December 2025, and HRSA has since sought stakeholder input on a revised approach. The manufacturer claims data requirements are happening in parallel, through private enforcement, without a uniform standard. The government has not resolved the rebate model question. It has not established uniform claims data reporting requirements. And manufacturers are not waiting.
The core problem is that what the 340B program actually needs is a single reporting standard: one set of data elements, one submission timeline, one enforcement framework. The manufacturers are not wrong that transparency and program integrity matter. What they are doing is implementing that transparency requirement on their own terms, one product portfolio at a time, in ways that are inconsistent with each other and cumulative in their burden on covered entities.
What CFOs Should Do Now
The Frier Levitt analysis offers practical guidance that every 340B CFO team should act on immediately.
If your organization expects to fall short of meeting a manufacturer's requirements, do not wait to be penalized. A covered entity that engages the manufacturer early, explaining specifically what data it can provide and what will require additional system work, may be able to negotiate a phased submission schedule that preserves 340B pricing while the organization builds out its reporting capability.
If your organization is already locked out of 340B pricing because a manufacturer says you are noncompliant, treat every resulting purchase at non-340B prices as a documented overcharge. That documentation creates a factual record you can bring to HRSA to seek enforcement action, including civil monetary penalties, against manufacturers conditioning 340B pricing on data submission.
Beyond those two immediate steps, the CFO's job is to look at the infrastructure question honestly.
Two-track decision framework for hospital CFOs managing 340B manufacturer noncompliance: steps for anticipated compliance gaps and steps after pricing has been suspended.
The Data Infrastructure Conversation Your Team Is Probably Not Having
Most hospital finance teams are treating the manufacturer claims data requirements as a pharmacy operations problem. It is not. It is a data infrastructure problem with a finance consequence.
The guidance published by HFMA lays out the infrastructure requirement clearly: your pharmacy information systems, EHR, and claims processing platforms need to be able to reconcile and report 340B drug transactions at the product or FDA National Drug Code level, reconcile inventory between in-house and contract pharmacies, and distinguish between 340B-eligible and non-eligible prescriptions. Each manufacturer policy potentially requires a variation on those capabilities, submitted on a different timeline, to a different data destination.
If your systems were not designed to produce that output cleanly, you are not going to solve this with a spreadsheet and a pharmacy compliance coordinator. The broader question of whether your financial systems are built for this kind of multi-source data environment is one I covered in depth in my piece on healthcare accounting software selection for CFOs. The evaluation criteria there apply directly to the 340B data production question.
You need to know what your current systems can actually produce, what the gap is between that output and each manufacturer's submission requirement, and what it will cost to close that gap. That cost belongs in your budget. Not as a vague compliance line item. As a specific project with a scope, a timeline, and a dollar amount attached to it.
The parallel to watch: the Change Healthcare disruption showed how quickly a third-party data dependency can translate into a cash flow crisis. I broke down the full financial exposure pattern in my piece on what the McKesson breach actually cost healthcare organizations. The lesson for 340B is the same. The organizations with documented system capabilities and vendor contract provisions came through with less damage than the ones that discovered their exposure after the fact.
The organizations that protect their 340B savings through this compliance cycle are not the ones that read every manufacturer announcement carefully. They are the ones that recognized early that the landscape was fragmenting and built the internal infrastructure to track a moving target.
If you want to think through what that infrastructure assessment looks like for your organization, I am glad to help. Start at hfi.consulting.
The 340B program has survived legal challenges, rebate model pilots, and congressional scrutiny. It will likely survive the current manufacturer enforcement wave as well. But that does not mean the cost of compliance is not real, or that covered entities can afford to treat each new manufacturer announcement as a standalone item.
What the program needs is a uniform reporting standard, established by HRSA or CMS, that gives manufacturers the transparency they are seeking while giving covered entities a single framework to build against. Until that standard exists, the compliance burden keeps accumulating, one manufacturer at a time.
Hospital CFOs who treat this as a systems and budget question now will be better positioned than those who treat it as a pharmacy department problem until the pricing gets cut off. If you want a framework for thinking through your organization's 340B data infrastructure readiness, HFI Consulting can help you work through that assessment. Start at hfi.consulting.
P.S. What is your 340B compliance tracking situation right now? Are you managing manufacturer requirements in a centralized system, or is this spread across pharmacy, compliance, and finance with no single owner? I read every reply.