Fraudsters Past and Present in CMS Crosshairs

Latest CMS effort is one of several new federal authorities. 

EDITOR’S NOTE: Former CMS career professional turned healthcare IT authority reported these developments Tuesday during Talk Ten Tuesday.

The Centers for Medicare & Medicaid Services (CMS) is taking a more proactive approach to reducing fraud and abuse in Medicare and other federal health programs. On Sept. 5, CMS issued a final rule, titled Program Integrity Enhancements to the Provider Enrollment Process (CMS-6058-FC). This rule strengthens the agency’s ability to stop fraud before it happens by keeping unscrupulous providers out of federal health insurance programs.

The rule creates several new authorities. A new “affiliations” authority in the rule allows CMS to identify individuals and organizations that pose an undue risk of fraud, waste, or abuse, based on their relationships with other previously sanctioned entities. For example, a currently enrolled or newly enrolling organization that has an owner/managing employee who is “affiliated” with another previously revoked organization can be denied enrollment in Medicare, Medicaid, and the Children’s Health Insurance Program (CHIP) – or, if already enrolled, it can have its enrollment revoked because of the problematic affiliation.  

Other authorities include the ability to deny enrollment if:

  • A provider or supplier circumvents program rules by coming back into the program, or attempting to come back in, under a different name (e.g. the provider attempts to “reinvent” itself);
  • A provider or supplier bills for services/items from non-compliant locations;
  • A provider or supplier exhibits a pattern or practice of abusive ordering or certifying of Medicare Part A or Part B items, services, or drugs; or
  • A provider or supplier has an outstanding debt to CMS from an overpayment that was referred to the U.S. Treasury Department.

These new authorities and restrictions are effective Nov. 4, 2019. 

As a reminder, a final rule “with comment” allows the rule to go into effect, but gives the public the opportunity to comment on the rule. The agency is under no obligation to respond to the comments or change the rule, but may do so if the comments warrant. In this case, the comments requested are for the section on affiliation and identifying provider affiliations. 

As part of CMS efforts to reduce fraud, abuse, and other claim errors, CMS has a Targeted Probe-and-Educate (TPE) program designed to help providers and suppliers reduce claim denials and appeals through one-on-one help. In this program, Medicare Administrative Contractors (MACs) use data analysis to identify providers and suppliers that have high claim error rates or unusual billing practices, and items and services that have high national error rates and are a financial risk to Medicare.

Providers whose claims are compliant with Medicare policy won’t be chosen for TPE. If chosen, providers have a small sample of claims reviewed, and if denials occur, then the provider is given one-on-one assistance to improve their billing. Some of the common errors include documentation not meeting medical necessity, incomplete certifications or recertifications, and encounter notes not supporting eligibility. 

And as a reminder during this hurricane season, as part of his declaration of a public health emergency (PHE), U.S. Department of Health and Human Services (HHS) Secretary Alex Azar has waived sanctions and penalties under certain provisions of the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule that may otherwise apply to covered hospitals, including provisions that generally require covered entities to give patients the opportunity to agree or object to sharing information with family members or friends involved in the patient’s care. This waiver applies only to the emergency area and for the emergency period identified in the PHE declaration, and only to hospitals that have instituted a disaster protocol. Qualifying hospitals can take advantage of the waiver for up to 72 hours from the time the hospital implements its disaster protocol unless the PHE declaration terminates first.

Even without a waiver, the Privacy Rule allows patient information to be shared to assist in disaster relief efforts, and to assist patients in receiving the care they need. As explained in more detail in the Office for Civil Rights’ (OCR’s) Bulletin on Hurricane Dorian and HIPAA linked below, the Privacy Rule permits covered entities to share information for treatment purposes, public health activities, and to prevent or lessen a serious and imminent threat to health or safety. The Privacy Rule also allows the sharing of information with patients’ family, friends, and others involved in their care in emergency situations to ensure proper care and treatment.

Facebook
Twitter
LinkedIn

Stanley Nachimson, MS

Stanley Nachimson, MS is principal of Nachimson Advisors, a health IT consulting firm dedicated to finding innovative uses for health information technology and encouraging its adoption. The firm serves a number of clients, including WEDI, EHNAC, the Cooperative Exchange, the Association of American Medical Colleges, and No World Borders. Stanley is focusing on assisting health care providers and plans with their ICD-10 implementation and is the director of the NCHICA-WEDI Timeline Initiative. He serves on the Board of Advisors for QualEDIx Corporation. Stanley served for over 30 years in the US Department of Health and Human Services in a variety of statistical, management, and health technology positions. His last ten years prior to his 2007 retirement were spent in developing HIPAA policy, regulations, and implementation planning and monitoring, beginning CMS’s work on Personal Health Records and serving as the CMS liaison with several industry organizations, including WEDI and HITSP. He brings a wealth of experience and information regarding the use of standards and technology in the health care industry.

Related Stories

Leave a Reply

Please log in to your account to comment on this article.

Featured Webcasts

Mastering Principal Diagnosis: Coding Precision, Medical Necessity, and Quality Impact

Mastering Principal Diagnosis: Coding Precision, Medical Necessity, and Quality Impact

Accurately determining the principal diagnosis is critical for compliant billing, appropriate reimbursement, and valid quality reporting — yet it remains one of the most subjective and error-prone areas in inpatient coding. In this expert-led session, Cheryl Ericson, RN, MS, CCDS, CDIP, demystifies the complexities of principal diagnosis assignment, bridging the gap between coding rules and clinical reality. Learn how to strengthen your organization’s coding accuracy, reduce denials, and ensure your documentation supports true medical necessity.

December 3, 2025

Proactive Denial Management: Data-Driven Strategies to Prevent Revenue Loss

Denials continue to delay reimbursement, increase administrative burden, and threaten financial stability across healthcare organizations. This essential webcast tackles the root causes—rising payer scrutiny, fragmented workflows, inconsistent documentation, and underused analytics—and offers proven, data-driven strategies to prevent and overturn denials. Attendees will gain practical tools to strengthen documentation and coding accuracy, engage clinicians effectively, and leverage predictive analytics and AI to identify risks before they impact revenue. Through real-world case examples and actionable guidance, this session empowers coding, CDI, and revenue cycle professionals to shift from reactive appeals to proactive denial prevention and revenue protection.

November 25, 2025
Sepsis: Bridging the Clinical Documentation and Coding Gap to Reduce Denials

Sepsis: Bridging the Clinical Documentation and Coding Gap to Reduce Denials

Sepsis remains one of the most frequently denied and contested diagnoses, creating costly revenue loss and compliance risks. In this webcast, Angela Comfort, DBA, MBA, RHIA, CDIP, CCS, CCS-P, provides practical, real-world strategies to align documentation with coding guidelines, reconcile Sepsis-2 and Sepsis-3 definitions, and apply compliant queries. You’ll learn how to identify and address documentation gaps, strengthen provider engagement, and defend diagnoses against payer scrutiny—equipping you to protect reimbursement, improve SOI/ROM capture, and reduce audit vulnerability in this high-risk area.

September 24, 2025

Trending News

Featured Webcasts

Surviving Federal Audits for Inpatient Rehab Facility Services

Surviving Federal Audits for Inpatient Rehab Facility Services

Federal auditors are zeroing in on Inpatient Rehabilitation Facility (IRF) and hospital rehab unit services, with OIG and CERT audits leading to millions in penalties—often due to documentation and administrative errors, not quality of care. Join compliance expert Michael Calahan, PA, MBA, to learn the five clinical “pillars” of IRF-PPS admissions, key documentation requirements, and real-life case lessons to help protect your revenue.

November 13, 2025
E/M Services Under Intensive Federal Scrutiny: Navigating Split/Shared, Incident-to & Critical Care Compliance in 2025-2026

E/M Services Under Intensive Federal Scrutiny: Navigating Split/Shared, Incident-to & Critical Care Compliance in 2025-2026

During this essential RACmonitor webcast Michael Calahan, PA, MBA Certified Compliance Officer, will clarify the rules, dispel common misconceptions, and equip you with practical strategies to code, document, and bill high-risk split/shared, incident-to & critical care E/M services with confidence. Don’t let audit risks or revenue losses catch your organization off guard — learn exactly what federal auditors are looking for and how to ensure your documentation and reporting stand up to scrutiny.

August 26, 2025

Trending News

Happy National Doctor’s Day! Learn how to get a complimentary webcast on ‘Decoding Social Admissions’ as a token of our heartfelt appreciation! Click here to learn more →

CYBER WEEK IS HERE! Don’t miss your chance to get 20% off now until Dec. 2 with code CYBER24