Fraudsters Past and Present in CMS Crosshairs

Latest CMS effort is one of several new federal authorities. 

EDITOR’S NOTE: Former CMS career professional turned healthcare IT authority reported these developments Tuesday during Talk Ten Tuesday.

The Centers for Medicare & Medicaid Services (CMS) is taking a more proactive approach to reducing fraud and abuse in Medicare and other federal health programs. On Sept. 5, CMS issued a final rule, titled Program Integrity Enhancements to the Provider Enrollment Process (CMS-6058-FC). This rule strengthens the agency’s ability to stop fraud before it happens by keeping unscrupulous providers out of federal health insurance programs.

The rule creates several new authorities. A new “affiliations” authority in the rule allows CMS to identify individuals and organizations that pose an undue risk of fraud, waste, or abuse, based on their relationships with other previously sanctioned entities. For example, a currently enrolled or newly enrolling organization that has an owner/managing employee who is “affiliated” with another previously revoked organization can be denied enrollment in Medicare, Medicaid, and the Children’s Health Insurance Program (CHIP) – or, if already enrolled, it can have its enrollment revoked because of the problematic affiliation.  

Other authorities include the ability to deny enrollment if:

  • A provider or supplier circumvents program rules by coming back into the program, or attempting to come back in, under a different name (e.g. the provider attempts to “reinvent” itself);
  • A provider or supplier bills for services/items from non-compliant locations;
  • A provider or supplier exhibits a pattern or practice of abusive ordering or certifying of Medicare Part A or Part B items, services, or drugs; or
  • A provider or supplier has an outstanding debt to CMS from an overpayment that was referred to the U.S. Treasury Department.

These new authorities and restrictions are effective Nov. 4, 2019. 

As a reminder, a final rule “with comment” allows the rule to go into effect, but gives the public the opportunity to comment on the rule. The agency is under no obligation to respond to the comments or change the rule, but may do so if the comments warrant. In this case, the comments requested are for the section on affiliation and identifying provider affiliations. 

As part of CMS efforts to reduce fraud, abuse, and other claim errors, CMS has a Targeted Probe-and-Educate (TPE) program designed to help providers and suppliers reduce claim denials and appeals through one-on-one help. In this program, Medicare Administrative Contractors (MACs) use data analysis to identify providers and suppliers that have high claim error rates or unusual billing practices, and items and services that have high national error rates and are a financial risk to Medicare.

Providers whose claims are compliant with Medicare policy won’t be chosen for TPE. If chosen, providers have a small sample of claims reviewed, and if denials occur, then the provider is given one-on-one assistance to improve their billing. Some of the common errors include documentation not meeting medical necessity, incomplete certifications or recertifications, and encounter notes not supporting eligibility. 

And as a reminder during this hurricane season, as part of his declaration of a public health emergency (PHE), U.S. Department of Health and Human Services (HHS) Secretary Alex Azar has waived sanctions and penalties under certain provisions of the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule that may otherwise apply to covered hospitals, including provisions that generally require covered entities to give patients the opportunity to agree or object to sharing information with family members or friends involved in the patient’s care. This waiver applies only to the emergency area and for the emergency period identified in the PHE declaration, and only to hospitals that have instituted a disaster protocol. Qualifying hospitals can take advantage of the waiver for up to 72 hours from the time the hospital implements its disaster protocol unless the PHE declaration terminates first.

Even without a waiver, the Privacy Rule allows patient information to be shared to assist in disaster relief efforts, and to assist patients in receiving the care they need. As explained in more detail in the Office for Civil Rights’ (OCR’s) Bulletin on Hurricane Dorian and HIPAA linked below, the Privacy Rule permits covered entities to share information for treatment purposes, public health activities, and to prevent or lessen a serious and imminent threat to health or safety. The Privacy Rule also allows the sharing of information with patients’ family, friends, and others involved in their care in emergency situations to ensure proper care and treatment.

Facebook
Twitter
LinkedIn

Stanley Nachimson, MS

Stanley Nachimson, MS is principal of Nachimson Advisors, a health IT consulting firm dedicated to finding innovative uses for health information technology and encouraging its adoption. The firm serves a number of clients, including WEDI, EHNAC, the Cooperative Exchange, the Association of American Medical Colleges, and No World Borders. Stanley is focusing on assisting health care providers and plans with their ICD-10 implementation and is the director of the NCHICA-WEDI Timeline Initiative. He serves on the Board of Advisors for QualEDIx Corporation. Stanley served for over 30 years in the US Department of Health and Human Services in a variety of statistical, management, and health technology positions. His last ten years prior to his 2007 retirement were spent in developing HIPAA policy, regulations, and implementation planning and monitoring, beginning CMS’s work on Personal Health Records and serving as the CMS liaison with several industry organizations, including WEDI and HITSP. He brings a wealth of experience and information regarding the use of standards and technology in the health care industry.

Related Stories

Special Bulletin

CMS Posts 80 New PCS Codes

The Centers for Medicare and Medicaid Services (CMS) have posted 80 new PCS codes.  To break it down, there are 24 new codes that are

Read More

Leave a Reply

Please log in to your account to comment on this article.

Featured Webcasts

Mastering OB GYN Coding Accuracy: Precision Coding for Compliance and Reimbursement

Gain clarity and confidence in OB‑GYN coding with this expert‑led webcast featuring Sherri L. Clayton, RHIT, CSS. You’ll learn how to apply global maternity package rules accurately, select the right CPT codes for procedures and visits, and identify documentation gaps that lead to denials. With practical guidance and real examples, this session helps you strengthen compliance, reduce audit risk, and ensure accurate reimbursement for women’s health services.

May 14, 2026

2026 ICD-10-CM/PCS Coding Clinic Update Webcast Series

Uncover essential coding insights with nationally recognized coding authority Kay Piper, RHIA, CDIP, CCS. Through ICD10monitor’s interactive, on‑demand webcast series, Kay walks you through the AHA’s 2026 ICD‑10‑CM/PCS Quarterly Coding Clinics, translating each update into practical, easy‑to‑apply guidance designed to sharpen precision, ensure compliance, and strengthen day‑to‑day decision‑making. Available shortly after each official release.

April 13, 2026

2026 ICD-10-CM/PCS Coding Clinic Update: Fourth Quarter

Uncover critical guidance on the ICD-10-CM/PCS code updates. Kay Piper reviews and explains ICD-10-CM/PCS coding guidelines in the AHA’s fourth quarter 2026 ICD-10-CM/PCS Coding Clinic in an easy to access on-demand webcast.

December 14, 2026

2026 ICD-10-CM/PCS Coding Clinic Update: Third Quarter

Uncover critical guidance on the ICD-10-CM/PCS code updates. Kay Piper reviews and explains ICD-10-CM/PCS coding guidelines in the AHA’s third quarter 2026 ICD-10-CM/PCS Coding Clinic in an easy to access on-demand webcast.

October 12, 2026

Trending News

Featured Webcasts

Compliance for the Inpatient Psychiatric Facility (IPF-PPS): Minimizing Federal Audit Findings by Strengthening Best Practices

Federal auditors are intensifying their focus on inpatient psychiatric facilities, using advanced data analytics to spotlight outliers and pursue high‑dollar repayments. In this high‑impact webcast, Michael Calahan, PA, MBA, Compliance Officer and V.P., Hospital & Physician Compliance, breaks down what regulators are really targeting in IPF-PPS admissions, documentation, treatment and discharge planning. Attendees will learn practical steps to tighten processes, avoid common audit triggers and protect reimbursement and reduce the risk of multimillion-dollar repayment demands.

April 9, 2026

Mastering MDM for Accurate Professional Fee Coding

In this timely session, Stacey Shillito, CDIP, CPMA, CCS, CCS-P, CPEDC, COPC, breaks down the complexities of Medical Decision Making (MDM) documentation so providers can confidently capture the true complexity of their care. Attendees will learn practical, efficient strategies to ensure documentation aligns with current E/M guidelines, supports accurate coding, and reduces audit risk, all without adding to charting time.

March 31, 2026

The PEPPER Returns – Risk and Opportunity at Your Fingertips

Join Ronald Hirsch, MD, FACP, CHCQM for The PEPPER Returns – Risk and Opportunity at Your Fingertips, a practical webcast that demystifies the PEPPER and shows you how to turn complex claims data into actionable insights. Dr. Hirsch will explain how to interpret key measures, identify compliance risks, uncover missed revenue opportunities, and understand new updates in the PEPPER, all to help your organization stay ahead of audits and use this powerful data proactively.

March 19, 2026

Top 10 Audit Targets for 2026-2027 for Hospitals & Physicians: Protect Your Revenue

Stay ahead of the 2026-2027 audit surge with “Top 10 Audit Targets for 2026-2027 for Hospitals & Physicians: Protect Your Revenue,” a high-impact webcast led by Michael Calahan, PA, MBA. This concise session gives hospitals and physicians clear insight into the most likely federal audit targets, such as E/M services, split/shared and critical care, observation and admissions, device credits, and Two-Midnight Rule changes, and shows how to tighten documentation, coding, and internal processes to reduce denials, recoupments, and penalties. Attendees walk away with practical best practices to protect revenue, strengthen compliance, and better prepare their teams for inevitable audits.

January 29, 2026

Trending News

Celebrate Lab Week with MedLearn! Sign up to win one year of our Laboratory All Access Pass! Click here to learn more →

Happy National Doctor’s Day! Learn how to get a complimentary webcast on ‘Decoding Social Admissions’ as a token of our heartfelt appreciation! Click here to learn more →

BLOOM INTO SAVINGS! Get 25% OFF during our spring sale through March 27. Use code SPRING26 at checkout to claim this offer.

CYBER WEEK IS HERE! Don’t miss your chance to get 20% off now until Dec. 1 with code CYBER25

CYBER WEEK IS HERE! Don’t miss your chance to get 20% off now until Dec. 2 with code CYBER24