Sunshine Act: New Transparency Obligations in the Healthcare Sector
Table of content
- 1. Why the Sunshine Act Was Born
- 2. The Subjective Scope: Who is Obliged to Report and Who Are the Beneficiaries?
- 3. The Objective Scope: Which Operations and With Which Thresholds?
- 4. The “Transparent Healthcare” Electronic Register
- 5. The Sanctioning Regime: Economic and Reputational Risks
- 6. Critical Intersections: GDPR and Model 231
- 7. State of Implementation: Where Do We Stand?
- 8. Operational Roadmap: What Companies Must Do Today
Recent Blogs
Cerchi supporto per la compliance al Sunshine Act?
Hai domande pratiche?
Dai un’occhiata alla nostra sezione Domande Frequenti per risposte chiare su scadenze, obblighi e strategie.
What changes in practical terms for companies, professionals, and healthcare organizations with the obligation to report to the Ministry of Health and publication on the “Transparent Healthcare” register?
With the law of May 31, 2022, no. 62 (known as the Italian Sunshine Act), the legislator introduced regulations aimed at making fully knowable the relationships of an economic nature or other benefits existing between “manufacturing” companies and subjects operating in the health sector.
From a practical and operational perspective, companies are called upon to retrieve, organize, filter, and transmit a significant volume of data that is currently fragmented across contracts, expense reports, procurement orders, consulting mandates, and invoices.
The purpose of the law is twofold:
- To guarantee transparency in the relationships between the industry and the healthcare supply chain;
- To prevent and counter corrupt phenomena and potential conflicts of interest.
1. Why the Sunshine Act Was Born
The regulatory premise rests on the recognition that economic and professional relationships between companies, doctors, and healthcare facilities directly impact the decision-making processes of spending, purchasing, and prescribing.
While in the past, transparency was primarily entrusted to industry self-regulation (such as the EFPIA code of ethics for the pharmaceutical industry), Law 62/2022 transforms this principle into a binding and public regulatory obligation. The collected data will, in fact, flow into a central database accessible to anyone, making every transfer of value traceable.
2. The Subjective Scope: Who is Obliged to Report and Who Are the Beneficiaries?
One of the most complex aspects of the regulation lies in the broad definitions adopted by the legislator.
Manufacturing Companies
Art. 2, paragraph 1, letter a) qualifies as a “manufacturing company” any entity that—even through intermediaries or affiliated companies—produces or markets:
- Drugs, medical instruments, or equipment;
- Goods or services, even of a non-healthcare nature, intended for human or veterinary health;
- Congress events and conferences focused on such products.
Attention to the Tech & Digital Health Ecosystem: The perimeter does not only concern pharmaceuticals and medical devices. It potentially includes IT/cloud service providers for healthcare, developers of artificial intelligence-based solutions, producers of nutraceuticals, and anyone providing economically appreciable services or benefits to healthcare facilities.
Subjects Operating in Health (HCP)
The qualification of HCP (Healthcare Professional) includes those who, regardless of title or classification, operate within a healthcare organization and:
- Have managerial or decision-making responsibilities in the allocation of resources;
- Intervene in decision-making processes relating to drugs, devices, goods, research, experimentation, or sponsorships.
Healthcare Organizations (HCO)
The category of Healthcare Organisation (HCO) includes:
- ASLs (Local Health Authorities), Hospital Companies, University Hospital Companies, and IRCCS (Scientific Institutes for Research, Hospitalization and Healthcare);
- Accredited and non-accredited private structures providing healthcare services;
- University departments and scientific research institutes;
- Scientific societies, professional orders, and accredited CME providers;
- Patient associations and foundations linked to such entities.
The Figure of the Intermediary
The law mandates the identification of the natural person who negotiated the terms of the agreement or maintained operational relations with the beneficiary on behalf of the company.
Since the law specifies that the intermediary can also be a company employee, it is essential not to indicate top roles by default (e.g., CEO, General Manager, Medical Director) if they did not manage the operation firsthand. The intermediary must be the individual actually capable of answering and accounting for the disbursement during an audit or inspection.
3. The Objective Scope: Which Operations and With Which Thresholds?
Art. 3 of the law provides for the reporting obligation for conventions, disbursements in cash, goods, services, or other benefits, as well as consulting agreements, teaching, and participation in scientific committees or congresses.
Minimum Reporting Thresholds
Operations are subject to a disclosure obligation upon exceeding the following limits:
| Recipient | Single Value Threshold |
Cumulative Annual Value Threshold
|
|---|---|---|
| HCP (Healthcare Professionals) | Over €100 | Over €1,000 |
| HCO (Healthcare Organizations) | Over €1,000 | Over €2,500 |
Note: Consulting, teaching, or research agreements are subject to reporting regardless of monetary value.
“Non-Monetary” Transfers of Value
The major interpretative criticality lies in benefits lacking an explicit or immediate monetary value. The cardinal rule is clear: if a company transfers an economically appreciable benefit to an HCP or an HCO, this operation potentially falls under the reporting obligation.
Among the most frequent concrete cases to be quantified at market value are:
- Free maintenance, tuning, and calibration on hospital machine parks;
- Reserved on-demand training courses and platforms;
- Translation services or submission fees for congress abstracts;
- Software platforms for project management or telemedicine support;
- Cloud credits or access to computational power provided for research projects;
- Diagnostic triage tools or clinical decision support algorithms based on AI granted for use.
4. The “Transparent Healthcare” Electronic Register
The data transmitted by companies will flow into the institutional portal “Sanità Trasparente” (Transparent Healthcare), managed by the Ministry of Health.
- Open Data: The portal will be publicly available for consultation and will allow the mass download and extraction of information in open data format.
- Retention: The data will remain published and accessible for 5 years from the date of entry.
- Cross-checking: Public availability will facilitate the cross-referencing of data with call for tenders, public assignment determinations, consulting assignments, and congress sponsorships.
The reliability and quality of the entered data become a primary safeguard for corporate compliance and reputation.
5. The Sanctioning Regime: Economic and Reputational Risks
Art. 6 of Law 62/2022 places the truthfulness of communication flows under the direct responsibility of the manufacturing company. Supervision is entrusted to the Ministry of Health with the support of the Carabinieri Command for Health Protection (NAS), the Financial Administration, and the Guardia di Finanza (Financial Police).
The foreseen sanctions are particularly incisive:
- Failure to declare: Fixed administrative fine of 1,000 euros, increased by 20 times the amount of the undeclared disbursement.
- Communication of false or untruthful data: Fine from 5,000 to 100,000 euros.
- Reputational sanction (Blacklist): Mandatory publication of the name of the sanctioned company directly on the Transparent Healthcare portal for a period of no less than 90 days.
6. Critical Intersections: GDPR and Model 231
Connection with Privacy Regulations (GDPR)
The law directly regulates the balance with Regulation (EU) 2016/679:
- Presumed consent: With the formalization of the agreement or the disbursement of the benefit between the provider and the recipient, the latter’s consent to publication is deemed legally given.
- Transparency notice: Companies must nevertheless fulfill the information obligation (art. 5, paragraph 6), formally informing the counterpart that the identification and economic data will be made public on the Ministry’s website, guaranteeing the exercise of the rights under articles 15-22 of the GDPR.
Integration into the Organizational Model Legislative Decree 231/2001
The Sunshine Act directly affects the preventive effectiveness of Model 231 regarding the crimes of:
- Corruption between private individuals (art. 2635 Italian Civil Code);
- Corruption of public officials or persons in charge of a public service (arts. 318-322 Italian Criminal Code).
The imposed transparency significantly restricts the spaces for concealing illicit payments. For this reason, it is essential that the Supervisory Bodies (OdV – Organismi di Vigilanza) include the verification of Sunshine Act flows in their periodic audit plans, and that companies integrate appropriate procedures into their 231 regulatory body.
7. State of Implementation: Where Do We Stand?
Law 62/2022 is formally in force; its full application effectiveness was subordinate to the technological infrastructure of the Transparent Healthcare portal.
The infrastructure has been developed and made available for technical trials and upload tests. The deadline for the formal start of the obligations will trigger in conjunction with the publication of the relevant official notice in the Official Gazette.
However, waiting for the formal deadline exposes companies to high risks: the obligations will be retroactive to the relevant operational semesters, making it essential to set up the collection of accounting and contractual evidence right now.
8. Operational Roadmap: What Companies Must Do Today
To minimize operational and sanctioning risks, companies must take action along 4 immediate guidelines:
- Preliminary mapping of relationships: Census contracts, consultancies, participation in faculties, scientific boards, donations, educational grants, and technological supply agreements with HCPs and HCOs.
- Revision of internal processes and procurement: Identify internal information sources (ERP management systems, CRM, expense report systems, contracts) and set up procedural filters to collect data at the source.
- Formalization of roles: Clearly appoint process owners and accurately map the operational “intermediaries” for each operation.
- Disclosure simulation and stress-test: Perform load testing and preventive reconciliation to intercept anomalies or documentation gaps before final submission.
Table of content
- 1. Why the Sunshine Act Was Born
- 2. The Subjective Scope: Who is Obliged to Report and Who Are the Beneficiaries?
- 3. The Objective Scope: Which Operations and With Which Thresholds?
- 4. The “Transparent Healthcare” Electronic Register
- 5. The Sanctioning Regime: Economic and Reputational Risks
- 6. Critical Intersections: GDPR and Model 231
- 7. State of Implementation: Where Do We Stand?
- 8. Operational Roadmap: What Companies Must Do Today
What changes in practical terms for companies, professionals, and healthcare organizations with the obligation to report to the Ministry of Health and publication on the “Transparent Healthcare” register?
With the law of May 31, 2022, no. 62 (known as the Italian Sunshine Act), the legislator introduced regulations aimed at making fully knowable the relationships of an economic nature or other benefits existing between “manufacturing” companies and subjects operating in the health sector.
From a practical and operational perspective, companies are called upon to retrieve, organize, filter, and transmit a significant volume of data that is currently fragmented across contracts, expense reports, procurement orders, consulting mandates, and invoices.
The purpose of the law is twofold:
- To guarantee transparency in the relationships between the industry and the healthcare supply chain;
- To prevent and counter corrupt phenomena and potential conflicts of interest.
1. Why the Sunshine Act Was Born
The regulatory premise rests on the recognition that economic and professional relationships between companies, doctors, and healthcare facilities directly impact the decision-making processes of spending, purchasing, and prescribing.
While in the past, transparency was primarily entrusted to industry self-regulation (such as the EFPIA code of ethics for the pharmaceutical industry), Law 62/2022 transforms this principle into a binding and public regulatory obligation. The collected data will, in fact, flow into a central database accessible to anyone, making every transfer of value traceable.
2. The Subjective Scope: Who is Obliged to Report and Who Are the Beneficiaries?
One of the most complex aspects of the regulation lies in the broad definitions adopted by the legislator.
Manufacturing Companies
Art. 2, paragraph 1, letter a) qualifies as a “manufacturing company” any entity that—even through intermediaries or affiliated companies—produces or markets:
- Drugs, medical instruments, or equipment;
- Goods or services, even of a non-healthcare nature, intended for human or veterinary health;
- Congress events and conferences focused on such products.
Attention to the Tech & Digital Health Ecosystem: The perimeter does not only concern pharmaceuticals and medical devices. It potentially includes IT/cloud service providers for healthcare, developers of artificial intelligence-based solutions, producers of nutraceuticals, and anyone providing economically appreciable services or benefits to healthcare facilities.
Subjects Operating in Health (HCP)
The qualification of HCP (Healthcare Professional) includes those who, regardless of title or classification, operate within a healthcare organization and:
- Have managerial or decision-making responsibilities in the allocation of resources;
- Intervene in decision-making processes relating to drugs, devices, goods, research, experimentation, or sponsorships.
Healthcare Organizations (HCO)
The category of Healthcare Organisation (HCO) includes:
- ASLs (Local Health Authorities), Hospital Companies, University Hospital Companies, and IRCCS (Scientific Institutes for Research, Hospitalization and Healthcare);
- Accredited and non-accredited private structures providing healthcare services;
- University departments and scientific research institutes;
- Scientific societies, professional orders, and accredited CME providers;
- Patient associations and foundations linked to such entities.
The Figure of the Intermediary
The law mandates the identification of the natural person who negotiated the terms of the agreement or maintained operational relations with the beneficiary on behalf of the company.
Since the law specifies that the intermediary can also be a company employee, it is essential not to indicate top roles by default (e.g., CEO, General Manager, Medical Director) if they did not manage the operation firsthand. The intermediary must be the individual actually capable of answering and accounting for the disbursement during an audit or inspection.
3. The Objective Scope: Which Operations and With Which Thresholds?
Art. 3 of the law provides for the reporting obligation for conventions, disbursements in cash, goods, services, or other benefits, as well as consulting agreements, teaching, and participation in scientific committees or congresses.
Minimum Reporting Thresholds
Operations are subject to a disclosure obligation upon exceeding the following limits:
| Recipient | Single Value Threshold |
Cumulative Annual Value Threshold
|
|---|---|---|
| HCP (Healthcare Professionals) | Over €100 | Over €1,000 |
| HCO (Healthcare Organizations) | Over €1,000 | Over €2,500 |
Note: Consulting, teaching, or research agreements are subject to reporting regardless of monetary value.
“Non-Monetary” Transfers of Value
The major interpretative criticality lies in benefits lacking an explicit or immediate monetary value. The cardinal rule is clear: if a company transfers an economically appreciable benefit to an HCP or an HCO, this operation potentially falls under the reporting obligation.
Among the most frequent concrete cases to be quantified at market value are:
- Free maintenance, tuning, and calibration on hospital machine parks;
- Reserved on-demand training courses and platforms;
- Translation services or submission fees for congress abstracts;
- Software platforms for project management or telemedicine support;
- Cloud credits or access to computational power provided for research projects;
- Diagnostic triage tools or clinical decision support algorithms based on AI granted for use.
4. The “Transparent Healthcare” Electronic Register
The data transmitted by companies will flow into the institutional portal “Sanità Trasparente” (Transparent Healthcare), managed by the Ministry of Health.
- Open Data: The portal will be publicly available for consultation and will allow the mass download and extraction of information in open data format.
- Retention: The data will remain published and accessible for 5 years from the date of entry.
- Cross-checking: Public availability will facilitate the cross-referencing of data with call for tenders, public assignment determinations, consulting assignments, and congress sponsorships.
The reliability and quality of the entered data become a primary safeguard for corporate compliance and reputation.
5. The Sanctioning Regime: Economic and Reputational Risks
Art. 6 of Law 62/2022 places the truthfulness of communication flows under the direct responsibility of the manufacturing company. Supervision is entrusted to the Ministry of Health with the support of the Carabinieri Command for Health Protection (NAS), the Financial Administration, and the Guardia di Finanza (Financial Police).
The foreseen sanctions are particularly incisive:
- Failure to declare: Fixed administrative fine of 1,000 euros, increased by 20 times the amount of the undeclared disbursement.
- Communication of false or untruthful data: Fine from 5,000 to 100,000 euros.
- Reputational sanction (Blacklist): Mandatory publication of the name of the sanctioned company directly on the Transparent Healthcare portal for a period of no less than 90 days.
6. Critical Intersections: GDPR and Model 231
Connection with Privacy Regulations (GDPR)
The law directly regulates the balance with Regulation (EU) 2016/679:
- Presumed consent: With the formalization of the agreement or the disbursement of the benefit between the provider and the recipient, the latter’s consent to publication is deemed legally given.
- Transparency notice: Companies must nevertheless fulfill the information obligation (art. 5, paragraph 6), formally informing the counterpart that the identification and economic data will be made public on the Ministry’s website, guaranteeing the exercise of the rights under articles 15-22 of the GDPR.
Integration into the Organizational Model Legislative Decree 231/2001
The Sunshine Act directly affects the preventive effectiveness of Model 231 regarding the crimes of:
- Corruption between private individuals (art. 2635 Italian Civil Code);
- Corruption of public officials or persons in charge of a public service (arts. 318-322 Italian Criminal Code).
The imposed transparency significantly restricts the spaces for concealing illicit payments. For this reason, it is essential that the Supervisory Bodies (OdV – Organismi di Vigilanza) include the verification of Sunshine Act flows in their periodic audit plans, and that companies integrate appropriate procedures into their 231 regulatory body.
7. State of Implementation: Where Do We Stand?
Law 62/2022 is formally in force; its full application effectiveness was subordinate to the technological infrastructure of the Transparent Healthcare portal.
The infrastructure has been developed and made available for technical trials and upload tests. The deadline for the formal start of the obligations will trigger in conjunction with the publication of the relevant official notice in the Official Gazette.
However, waiting for the formal deadline exposes companies to high risks: the obligations will be retroactive to the relevant operational semesters, making it essential to set up the collection of accounting and contractual evidence right now.
8. Operational Roadmap: What Companies Must Do Today
To minimize operational and sanctioning risks, companies must take action along 4 immediate guidelines:
- Preliminary mapping of relationships: Census contracts, consultancies, participation in faculties, scientific boards, donations, educational grants, and technological supply agreements with HCPs and HCOs.
- Revision of internal processes and procurement: Identify internal information sources (ERP management systems, CRM, expense report systems, contracts) and set up procedural filters to collect data at the source.
- Formalization of roles: Clearly appoint process owners and accurately map the operational “intermediaries” for each operation.
- Disclosure simulation and stress-test: Perform load testing and preventive reconciliation to intercept anomalies or documentation gaps before final submission.
Recent Blogs
Cerchi supporto per la compliance al Sunshine Act?
Hai domande pratiche?
Dai un’occhiata alla nostra sezione Domande Frequenti per risposte chiare su scadenze, obblighi e strategie.



