Fraudsters Past and Present in CMS Crosshairs

Latest CMS effort is one of several new federal authorities. 

EDITOR’S NOTE: Former CMS career professional turned healthcare IT authority reported these developments Tuesday during Talk Ten Tuesday.

The Centers for Medicare & Medicaid Services (CMS) is taking a more proactive approach to reducing fraud and abuse in Medicare and other federal health programs. On Sept. 5, CMS issued a final rule, titled Program Integrity Enhancements to the Provider Enrollment Process (CMS-6058-FC). This rule strengthens the agency’s ability to stop fraud before it happens by keeping unscrupulous providers out of federal health insurance programs.

The rule creates several new authorities. A new “affiliations” authority in the rule allows CMS to identify individuals and organizations that pose an undue risk of fraud, waste, or abuse, based on their relationships with other previously sanctioned entities. For example, a currently enrolled or newly enrolling organization that has an owner/managing employee who is “affiliated” with another previously revoked organization can be denied enrollment in Medicare, Medicaid, and the Children’s Health Insurance Program (CHIP) – or, if already enrolled, it can have its enrollment revoked because of the problematic affiliation.  

Other authorities include the ability to deny enrollment if:

  • A provider or supplier circumvents program rules by coming back into the program, or attempting to come back in, under a different name (e.g. the provider attempts to “reinvent” itself);
  • A provider or supplier bills for services/items from non-compliant locations;
  • A provider or supplier exhibits a pattern or practice of abusive ordering or certifying of Medicare Part A or Part B items, services, or drugs; or
  • A provider or supplier has an outstanding debt to CMS from an overpayment that was referred to the U.S. Treasury Department.

These new authorities and restrictions are effective Nov. 4, 2019. 

As a reminder, a final rule “with comment” allows the rule to go into effect, but gives the public the opportunity to comment on the rule. The agency is under no obligation to respond to the comments or change the rule, but may do so if the comments warrant. In this case, the comments requested are for the section on affiliation and identifying provider affiliations. 

As part of CMS efforts to reduce fraud, abuse, and other claim errors, CMS has a Targeted Probe-and-Educate (TPE) program designed to help providers and suppliers reduce claim denials and appeals through one-on-one help. In this program, Medicare Administrative Contractors (MACs) use data analysis to identify providers and suppliers that have high claim error rates or unusual billing practices, and items and services that have high national error rates and are a financial risk to Medicare.

Providers whose claims are compliant with Medicare policy won’t be chosen for TPE. If chosen, providers have a small sample of claims reviewed, and if denials occur, then the provider is given one-on-one assistance to improve their billing. Some of the common errors include documentation not meeting medical necessity, incomplete certifications or recertifications, and encounter notes not supporting eligibility. 

And as a reminder during this hurricane season, as part of his declaration of a public health emergency (PHE), U.S. Department of Health and Human Services (HHS) Secretary Alex Azar has waived sanctions and penalties under certain provisions of the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule that may otherwise apply to covered hospitals, including provisions that generally require covered entities to give patients the opportunity to agree or object to sharing information with family members or friends involved in the patient’s care. This waiver applies only to the emergency area and for the emergency period identified in the PHE declaration, and only to hospitals that have instituted a disaster protocol. Qualifying hospitals can take advantage of the waiver for up to 72 hours from the time the hospital implements its disaster protocol unless the PHE declaration terminates first.

Even without a waiver, the Privacy Rule allows patient information to be shared to assist in disaster relief efforts, and to assist patients in receiving the care they need. As explained in more detail in the Office for Civil Rights’ (OCR’s) Bulletin on Hurricane Dorian and HIPAA linked below, the Privacy Rule permits covered entities to share information for treatment purposes, public health activities, and to prevent or lessen a serious and imminent threat to health or safety. The Privacy Rule also allows the sharing of information with patients’ family, friends, and others involved in their care in emergency situations to ensure proper care and treatment.

Facebook
Twitter
LinkedIn

Stanley Nachimson, MS

Stanley Nachimson, MS is principal of Nachimson Advisors, a health IT consulting firm dedicated to finding innovative uses for health information technology and encouraging its adoption. The firm serves a number of clients, including WEDI, EHNAC, the Cooperative Exchange, the Association of American Medical Colleges, and No World Borders. Stanley is focusing on assisting health care providers and plans with their ICD-10 implementation and is the director of the NCHICA-WEDI Timeline Initiative. He serves on the Board of Advisors for QualEDIx Corporation. Stanley served for over 30 years in the US Department of Health and Human Services in a variety of statistical, management, and health technology positions. His last ten years prior to his 2007 retirement were spent in developing HIPAA policy, regulations, and implementation planning and monitoring, beginning CMS’s work on Personal Health Records and serving as the CMS liaison with several industry organizations, including WEDI and HITSP. He brings a wealth of experience and information regarding the use of standards and technology in the health care industry.

Related Stories

Leave a Reply

Please log in to your account to comment on this article.

Featured Webcasts

Trending News

Featured Webcasts

Ask Dr. Hirsch: Clarifying Medicare’s Most Misunderstood Rules – Part 2

Medicare regulations are complex and even seasoned professionals struggle to apply them consistently. Due to overwhelming demand, Dr. Hirsch returns for Part 2 of Ask Dr. Hirsch: Clarifying Medicare’s Most Misunderstood Rules to answer even more of Medicare’s most misunderstood questions, covering inpatient status, observation, SNF access, Medicare Advantage denials, and more. Join Dr. Hirsch as he provides clear, referenced answers to real-world questions submitted by your peers, helping you navigate Medicare compliance with confidence and clarity.

June 18, 2026

Reengineering Utilization Management: Building an Adaptive Model for the New Payer Era

Traditional utilization management models can no longer keep pace with regulatory shifts, payer scrutiny, and operational pressures. In this webcast, Tiffany Ferguson, LMSW, CMAC, ACM, ACPA-C, introduces an Adaptive Model strategy that modernizes UM through role specialization, technology-driven workflows, and proactive, team-based processes. Attendees will learn how to restructure programs to improve efficiency, strengthen clinical collaboration, and enhance financial performance in a rapidly changing healthcare environment.

May 20, 2026

Compliance for the Inpatient Psychiatric Facility (IPF-PPS): Minimizing Federal Audit Findings by Strengthening Best Practices

Federal auditors are intensifying their focus on inpatient psychiatric facilities, using advanced data analytics to spotlight outliers and pursue high‑dollar repayments. In this high‑impact webcast, Michael Calahan, PA, MBA, Compliance Officer and V.P., Hospital & Physician Compliance, breaks down what regulators are really targeting in IPF-PPS admissions, documentation, treatment and discharge planning. Attendees will learn practical steps to tighten processes, avoid common audit triggers and protect reimbursement and reduce the risk of multimillion-dollar repayment demands.

April 9, 2026

Mastering MDM for Accurate Professional Fee Coding

In this timely session, Stacey Shillito, CDIP, CPMA, CCS, CCS-P, CPEDC, COPC, breaks down the complexities of Medical Decision Making (MDM) documentation so providers can confidently capture the true complexity of their care. Attendees will learn practical, efficient strategies to ensure documentation aligns with current E/M guidelines, supports accurate coding, and reduces audit risk, all without adding to charting time.

March 31, 2026

Trending News

Celebrate Lab Week with MedLearn! Sign up to win one year of our Laboratory All Access Pass! Click here to learn more →

Have a Medicare regulation question you’d love Dr. Hirsch to answer? Now is your chance! CLICK HERE to learn more→

Happy National Doctor’s Day! Learn how to get a complimentary webcast on ‘Decoding Social Admissions’ as a token of our heartfelt appreciation! Click here to learn more →

This Memorial Day, we honor those who gave all for our freedom. Take 20% off sitewide through May 29 with code MEMORIAL26 at checkout

CYBER WEEK IS HERE! Don’t miss your chance to get 20% off now until Dec. 1 with code CYBER25

CYBER WEEK IS HERE! Don’t miss your chance to get 20% off now until Dec. 2 with code CYBER24