HHS OIG Compliance News

HHS-OIG Urges CMS & MA Organziations Increase Efforts to Prevent Durable Medical Equipment Fraud

Each year, millions of taxpayers’ dollars are lost to Medicare and Medicaid fraud, with fraud related to durable medical equipment, prosthetics, orthotics, and supplies (DMEPOS) a major problem. In one case alone, the largest ever healthcare fraud loss charged by the Department of Justice, an 11-person, Russia-based transnational network attempted to defraud Medicare out of $10.6 billion through fraudulent DMEPOS billings.

DMEPOS-related healthcare fraud is a longstanding problem for the Original Medicare program; however, HHS-OIG has identified fraud schemes targeting Medicare Advantage and warns that DMEPOS fraud could put the program at risk. Currently, more than half of all Medicare recipients, around 34 million individuals, are enrolled in the Medicare Advantage (MA) program. The MA program involves the government paying private health insurance companies – MA organizations – to provide coverage to Medicare enrollees. MA organizations may create networks of providers and DMEPOS suppliers, and contract with those organizations. Other suppliers can provide DMEPOS that do not contract with MA organizations – out-of-network suppliers. The responsibility for preventing fraudulent DMEPOS Medicare Advantage billing by in-network and out-of-network DMEPOS suppliers is shared by the CMS and MA organizations.

An HHS-OIG investigation looked at six MA organizations to examine fraud risk and the steps the CMS and MA organizations are taking to prevent DMEPOS-related healthcare fraud. The investigation identified several gaps in screening, which could allow fraudulent suppliers to bill the MA program. The six MA organizations provide coverage for around two-thirds of all MA enrollees and manage more than 21,000 DMEPOS suppliers. Around 8,000 suppliers billed in-network, and the remaining 13,000 always billed out-of-network.

While the Original Medicare program required all suppliers to be enrolled in Medicare, under the MA program, MA organizations can allow some DMEPOS suppliers that are not enrolled in Medicare to bill them. MA organizations conduct some checks of all in-network suppliers; however, fewer checks are conducted of out-of-network suppliers, and with limited scrutiny of out-of-network DMEPOS suppliers, there is an increased risk of fraudulent billing.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

For instance, some checks are required of all in-network DMEPOS suppliers, such as verifying that a supplier has a state license, should one be required; verifying that a supplier has been reviewed and approved by an accrediting body or meets the standards of the MA organization; and confirming that a supplier is not on the CMS Preclusion List and has not been excluded from participation in healthcare programs by HHS-OIG. Some MA organizations require additional checks on in-network suppliers.

The required checks for out-of-network DMEPOS suppliers are far less stringent. While checks must be made to ensure that they are not on the CMS Preclusion List, out-of-network suppliers are not required to be checked to ensure that they meet State licensure requirements or that the suppliers are accredited. Only three of the six MA organizations said they check to ensure that suppliers have appropriate State licenses.

Screening gaps were also identified at the CMS. Unlike Original Medicare, the CMS does not screen all DMEPOS suppliers that bill Medicare Advantage, because not all DMEPOS suppliers are enrolled in Medicare. In order to enrol in Medicare, screening checks must be successfully completed. Without that screening process, there is an increased risk of fraud. CMS relies on the Preclusion List for preventing fraud; however, HHS-OIG warned that using the Preclusion List is only effective at reactively stopping suppliers from fraudulently billing. Fraudulent billing can be stopped once it has been identified, but it does not proactively prevent fraudulent billing. Further, CMS was not using the Preclusion List to its full extent.

According to HHS-OIG, the average amount billed per enrollee for orthotics by in-network suppliers was $210, whereas the average amount billed by out-of-network non-enrolled suppliers was $1,399 – seven times more than in-network suppliers. In HHS-OIG interviews with MA organizations, three said DMEPOS fraud schemes impacting their plans often involved out-of-network suppliers, and two said out-of-network suppliers accounted for almost all MA fraud schemes.

Further, out-of-network suppliers can rapidly start submitting claims without the required checks involved in enrolling in Medicare. CMS staff reported that “bad actors can incorporate a DMEPOS company and get a National Provider Identifier within a few days, which allows them to start billing MAOs almost immediately.” In some cases, “suppliers pop up relatively quickly, bill fast, and then exit.”

HHS-OIG said the most effective way of combating DMEPOS-related fraud is to prevent bad actors from billing in the first place, and as such, preventative efforts need to be stepped up by both the CMS and MA organizations. HHS-OIG recommends that MA organizations strengthen checks of out-of-network DMEPOS suppliers, and strengthen the use of the Preclusion List to prevent fraudulent DMEPOS suppliers from billing the MA program. HHS-OIG recommended that the CMS require all DMEPOS suppliers that bill Medicare Advantage to be enrolled in Medicare, and if not permitted under current law, to seek statutory authority to do so. The CMS concurred with all recommendations.

The post HHS-OIG Urges CMS & MA Organziations Increase Efforts to Prevent Durable Medical Equipment Fraud appeared first on The HIPAA Journal.

New HHS-OIG Exclusions

The Department of Health and Human Services Office of Inspector General (HHS-OIG) has announced new additions to its List of Excluded Individuals and Entities (LEIE). The LEIE, often referred to as the HHS-OIG exclusion list, is a centralized registry for individuals and entities that have been prohibited from participating in federally funded healthcare programs, including Medicare and state healthcare programs.

There are mandatory exclusions for individuals and entities convicted of criminal offenses such as Medicare or Medicaid fraud, patient abuse or neglect, and for felony convictions for other health care-related fraud, theft, or other financial misconduct, and felony convictions related to the unlawful manufacture, distribution, prescription, and dispensing of controlled substances. HHS-OIG also has the authority to exclude individuals and entities on other grounds, termed permissible inclusions. Reasons for permissive inclusions include misdemeanor convictions, engaging in unlawful kickbacks, suspension or revocation of a healthcare license, and defaulting on health education loans or scholarship obligations.

If an excluded individual or entity continues to work in the healthcare industry and participates in a federally funded healthcare program, they can face criminal prosecution, fines, permanent loss of licensure, or disbarment. An employer can face substantial civil monetary penalties, triple damages for all items and services claimed in connection with that individual or entity, and potentially loss of all federal funding or costly and highly intrusive ongoing monitoring by HHS-OIG.

Each healthcare entity is responsible for ensuring that no new hires or existing employees are excluded. The LEIE must be checked prior to any hire, and routine checks should be conducted to ensure that no current employee has been added to the LEIE.

The following entities and individuals have recently been added to the LEIE:

Myers Southern – Myers Southern, LLC, of Bartow, Florida, was excluded for a period of 7 years from participation in federally funded health care programs for failing to respond to an HHS-OIG subpoena that was necessary to determine whether Medicare payments were due, and the amounts associated with those payments.

Dr. Nathan Hanflink and Pain Management Institute – Dr. Nathan Hanflink and Pain Management Institute in Florida, have been excluded from participation in federally funded healthcare programs for 5 years following an HHS-OIG investigation that determined they submitted claims to Medicare Part B for chronic care management services that were never rendered.

Sunshine Care Partners and Rusty McMurray – Sunshine Care Partners, and owner Rusty McMurray have been excluded from participation in healthcare programs for 10 years after knowingly submitting claims for complex chronic care management services for individuals who were never provided with those services. According to HHS-OIG, those complex care management services only involved having employees take the temperature of all individuals entering the facility, sanitizing and cleaning front desk areas, and organizing paperwork.

The post New HHS-OIG Exclusions appeared first on The HIPAA Journal.

HHS-OIG Identifies Security Deficiencies in Audit of VA Spokane Healthcare System

An audit of the Department of Veterans’ Affairs Spokane Healthcare System in Washington state by the Department of Health and Human Services Office of Inspector General (HHS-OIG) identified deficiencies in all three control areas inspected: configuration management, security management, and access controls. The audit was conducted on the Mann-Grandstaff VA Medical Center between January 29 and February 6, 2025, which has approximately 1,300 employees and provided care to 27,000 patients in fiscal year 2024.

There were several instances where staff failed to remediate critical and high-severity vulnerabilities within the 60-day time frame stipulated by the VA, and in some cases had failed to develop the required action plans to remediate those vulnerabilities within that time frame. HHS-OIG also identified systems that were running unsupported software, and several devices were identified that had not been configured to VA-approved security baselines. These deficiencies increased the risk of unauthorized access and operational disruption, especially the failure to meet the security baselines on databases and core network devices.

One deficiency was identified in security management regarding the protection of personally identifiable information (PII). A screen with unredacted PII in the federal electronic health record (EHR) could be viewed by volunteers and scheduling clerks, who did not require access to that information. The failure to restrict access puts PII at risk, which could potentially be misused to cause harm to veterans.

Four access control deficiencies were identified related to physical and logical access to IT resources. There was a lack of proper segregation of duties for key distribution, unsecured network equipment was identified in two locations, eleven communications sockets did not have proper electrical grounding, and perimeter protection measures for fuel storage did not meet VA guidelines.

HHS-OIG made 7 recommendations in the areas of configuration management, security management, and access controls, which HHS-OIG said are also applicable to other VA facilities. The VA has already implemented some of the recommendations and has planned to address the remaining issues.

The post HHS-OIG Identifies Security Deficiencies in Audit of VA Spokane Healthcare System appeared first on The HIPAA Journal.

Failure to Provide a Medical Screening Examination Results in HHS-OIG Penalty

Two hospitals have entered into settlement agreements with the Department of Health and Human Services (HHS) Office of Inspector General (OIG) to resolve alleged violations of the Emergency Medical Treatment and Labor Act (EMTALA).

EMTALA requires Medicare-participating hospitals with emergency departments to provide a medical screening examination and stabilizing treatment for any patient, regardless of the patient’s ability to pay. Patients must not be transferred unless they have first been provided with stabilizing treatment, unless the patient requests a transfer in writing, the benefits outweigh the risks, and if the receiving hospital agrees to accept the patient. Transfers are also permitted if the hospital does not have the capabilities to stabilize the patient, in which case, the patient can be transferred to a hospital with specialized capabilities.

Cordell Memorial Hospital in Oklahoma was investigated by HHS-OIG after an alleged failure to provide a medical screening examination to a pregnant patient in active labor, who presented at the hospital on January 27, 2026. The woman arrived at the hospital in a private vehicle and was having contractions every 1-2 minutes. Staff at Cordell Memorial Hospital’s Emergency Department met the patient outside the facility and asked if the patient’s waters had broken and if there was an immediate need to push. When the patient responded in the negative to both questions, the ED staff recommended that the patient travel to an alternative facility 15 miles away.

The patient did not receive a pelvic examination, and her vital signs were not checked; therefore staff could not make an accurate determination about whether there was time to travel to the other healthcare facility or if the transfer posed a threat to the health and safety of the patient or their unborn child. The child was delivered within approximately 40 minutes of arriving at the other hospital. HHS-OIG determined that the failure to provide a medical screening examination was in violation of EMTALA, and the case was settled with a $40,000 financial penalty.

Holmes Regional Medical Center in Melbourne, Florida, was similarly investigated over an incident involving a pregnant patient, who presented at the Emergency Department 30 weeks pregnant seeking an examination and treatment for high blood pressure. The patient was accompanied by a minor child of approximately 4-6 years of age. As the patient was completing the intake form, a security guard told the patient that the minor child was not permitted to be present in the triage area. As a result, the patient left the ED without having an appropriate medical screening examination. HHS-OIG determined that the failure to provide the MSE was in violation of EMTALA. The alleged violation was settled, with Holmes Regional Medical Center agreeing to pay a $113,407 financial penalty.

The post Failure to Provide a Medical Screening Examination Results in HHS-OIG Penalty appeared first on The HIPAA Journal.

HHS-OIG Report Highlights Key HHS Cybersecurity Challenges

The U.S. Department of Health and Human Services Office of Inspector General has published its annual report on the Top Management and Performance Challenges Facing HHS to help the department improve the effectiveness and efficiency of its programs. The report highlights some of the cybersecurity challenges faced by HHS, including a lack of standardized governance and controls, which complicates HHS’s preparedness efforts to prevent and respond to cybersecurity threats.

The HHS is a large department with disparate organizational approaches to cybersecurity across its various divisions and programs. While the department has taken steps to consolidate cybersecurity functions and improve cybersecurity, HHS-OIG says overall progress is often still dependent on each division and program. In addition, the HHS has an army of contractors, grantees, and other external entities that number in the thousands. Cybersecurity solutions must be implemented within the HHS, but also by each contractor, grantee, and external entity. That makes cybersecurity improvements especially challenging, and the ability of the HHS to mitigate cybersecurity threats is often dependent on those entities implementing cybersecurity solutions specific to their operations. “Protecting technology and data requires broader efforts beyond implementing technical fixes, such as establishing clear expectations; modernizing program rules; and conducting effective oversight of the Department’s contractors, grantees, and other external entities,” HHS-OIG said.

The healthcare sector remains a key target for cyber actors. Ransomware attacks continue in volume, as financially motivated threat actors encrypt and steal data to use as leverage to obtain ransom payments. Cyberattacks are growing in sophistication and are continually evolving, and the HHS must be able to respond quickly, alert the sector about vulnerabilities under exploitation, and help prepare the sector for evolving threats.

The HHS plays a key role in improving cybersecurity across the sector and responding to threats, yet the diffuse nature of HHS cybersecurity authorities and responsibilities is complicating HHS’s response efforts. The HHS has limited resources for improving cybersecurity across the healthcare and public health sector, such as the sector’s reliance on legacy technology and workforce challenges. Further, privacy and security are governed by HIPAA, which is more than two decades old. HHS-OIG warned that the HIPAA Privacy Rule and the HIPAA Security Rule may not be sufficient to address contemporary privacy concerns and the increasing cybersecurity risks to electronic protected health information. As such, HHS-OIG said the HHS must adapt as privacy and security needs evolve.

Further regulation could help in this regard; however, the HHS has been slow to enact updates to the HIPAA Rules. A Privacy Rule update was proposed by HHS under the previous Trump administration in late 2020, yet a final rule has still not been published more than five years after the update was first proposed. The update is still on the HHS’s agenda, but there has been no indication when a final rule will be published. An extensive update to modernize the HIPAA Security Rule to strengthen cybersecurity across the sector was proposed in the final days of the Biden administration. While there is an urgent need to improve cybersecurity across the sector, it is currently unclear if the HHS, under the Trump administration, plans on implementing the proposed rule.

HHS-OIG said the HHS has taken action to address the challenges it highlights in the report, but there are considerable opportunities for further progress, and until the HIPAA Rules are updated, HHS must continue to work within the statutory authorities established by HIPAA in 1996, the HIPAA Privacy Rule in 2000, and the HIPAA Security Rule in 2003.

The post HHS-OIG Report Highlights Key HHS Cybersecurity Challenges appeared first on The HIPAA Journal.

AccuCare Home Health Services Pays $20,000 Fine for Employing Excluded Individual

The Department of Health and Human Services Office of Inspector General (HHS-OIG) has agreed to a $20,000 settlement with AccuCare Home Health Services to resolve allegations that the home healthcare provider employed an individual on the HHS-OIG exclusions list and billed services provided by that individual to federally funded healthcare programs.

AccuCare Home Health Services is a Mesa, Arizona-based provider of home health care services, specializing in skilled nursing, physical therapy, occupational therapy, speech therapy, and medical social services. According to HHS-OIG, AccuCare Home Health Services was discovered to have employed a home healthcare aide who was not permitted to participate in any federally funded healthcare program, and billed products or services provided by that individual to federal health care programs. The alleged violation was settled with a $20,000 financial penalty.

Healthcare organizations must ensure that a check is conducted of the HHS-OIG List of Excluded Individuals and Entities (LEIE) prior to onboarding a new employee. Regular checks must also be conducted on all employees, since individuals may be added to the LEIE after their employment commences. The HHS’ Office for Civil Rights imposes relatively few financial penalties for HIPAA violations; however, when it comes to HHS OIG compliance, there is a much greater risk of a financial penalty if violations are identified. HHS-OIG regularly imposes significant financial penalties for claiming for items and services provided by excluded individuals and companies, submitting false claims, and violations of the Stark Law and the Anti-Kickback Statute. In addition to a financial penalty, there is a risk of being added to the HHS exclusion list, which will prohibit an individual or company from participating in federally funded health care programs.

On November 12, 2025, HHS-OIG announced that William Mangan, DO (Dr. Mangan) of Okemos, Michigan, had agreed to be excluded from participating in federally funded healthcare programs for a period of 10 years in connection with False Claims Act violations. Dr. Mangan was investigated by HHS-OIG in connection with allegations that he ordered genetic tests, durable medical equipment, prosthetics, orthotics, and supplies (DMEPOS) that were not reasonable or medically necessary and submitted claims to federally funded health care programs. Dr. Mangan claimed that he had evaluated patients and falsely certified that the ordered products were medically necessary when he failed to perform an adequate review.

Individuals can face severe penalties for knowingly causing products or services to be billed to federally funded healthcare programs when they are on the HHS-OIG exclusion list. Erik X. Alonso, 55, of Miami, Florida, had been convicted of conspiracy to commit health care fraud in 2015 for offenses in the Southern District of Florida. As a result of the conviction, Alonso was placed on the exclusion list and was fully aware that he was prohibited from participating in work that was billed to federally funded healthcare programs. In March 2022, Alonso started working for a telehealth mental health provider in New Hampshire and provided services to patients in the state that he knew would be billed to Medicaid. Alonso caused New Hampshire Medicaid to pay approximately $173,998.83 based on false and fraudulent claims. The healthcare fraud was discovered, and Alonso entered a guilty plea to one count of healthcare fraud and is awaiting sentencing. He now faces up to 10 years in jail.

The post AccuCare Home Health Services Pays $20,000 Fine for Employing Excluded Individual appeared first on The HIPAA Journal.

Audit Uncovers Security Weaknesses in the NIH All of Us Security Program

An audit of the National Institutes of Health (NIH) All of Us Research Program has uncovered privacy and security weaknesses that put the health information of more than 1 million individuals at risk of compromise.

The All of Us Research Program was launched in 2015 as part of the NIH Precision Medicine Initiative to advance disease prevention and treatment by making the personal health and genomics data of more than 1 million individuals available for research purposes. Unlike research studies that focus on a specific disease or cohort of people, the All of Us Research database can be used to study a wide range of health conditions and diseases. The data is housed by the Data and Research Center (DRC) and is managed by an NIH award recipient, Vanderbilt University Medical Center. The All of Us database is one of the largest health research databases of its kind.

While general data about the entire group of participants can be viewed by anyone, only researchers approved by the All of Us Research Program are allowed to view data from individual participants. Such a large database of health information is extremely valuable; therefore, robust privacy and security measures must be implemented to protect research participants’ data from cybersecurity and national security threats.

The Department of Health and Human Services Office of Inspector General (HHS-OIG) has recently published the findings of a 2024 audit that sought to determine whether appropriate access controls had been implemented by the DRC award recipient, if appropriate privacy and security controls were in place, and if information security and privacy weaknesses had been addressed in accordance with federal standards.

HHS-OIG determined that the DRC award recipient had implemented some cybersecurity controls, including vulnerability scanning, penetration testing, flaw remediation, system monitoring, incident response, contingency planning, disaster recovery, and security awareness training; however, controls were inadequate in some areas, which put research participants’ data at an increased risk of compromise.

HHS-OIG identified access control weaknesses. For instance, while authorized users were permitted to remotely access the information systems from foreign countries with prior approval, there were no controls in place to restrict access to only the individuals who had received approval. As such, any authorized user could access the information systems from a foreign country. While downloads of detailed participants’ data are prohibited, there were no access controls in place to prevent data downloads.

HHS-OIG also found that the DRC award recipient failed to communicate national security concerns associated with the maintenance of genomic data to NIH and did not resolve identified weaknesses and vulnerabilities within the timeframe stipulated by NIH in its award agreement. As such, there was an increased risk of research participants’ data, including genomic data, being accessed, downloaded, and misused by bad actors, including foreign adversaries.

HHS-OIG made five recommendations to NIH to improve oversight of the All of Us Research Program and address the identified privacy and security issues. NIH concurred with all five recommendations and is implementing measures to address the privacy and security weaknesses. NIH has confirmed that measures already fully implemented include controls to resolve the remote access security issues, and access from certain countries of concern has been blocked, including China, Cuba, Iran, Russia, and North Korea.

The post Audit Uncovers Security Weaknesses in the NIH All of Us Security Program appeared first on The HIPAA Journal.

State Medicaid Agencies Need to Improve Security Controls for MMIS and E&E Systems

Penetration tests conducted on ten State Medicaid Management Information Systems (MMIS) and Eligibility & Enrollment (E&E) systems have revealed they contain vulnerabilities that could potentially be exploited in sophisticated cyberattacks. The penetration tests were conducted on behalf of the Department of Health and Human Services’ Office of Inspector General (HHS-OIG) by a third-party penetration testing company between 2020 and 2022 to determine the effectiveness of information technology system controls in preventing attacks on web-facing MMIS and E&E systems.

The penetration tests were conducted in response to an increase in cyberattacks targeting MMIS and E&E systems. These systems are attractive targets as they contain significant amounts of valuable and sensitive data. HHS-OIG has observed an increase in multiple threat types targeting these systems, including ransomware attacks, phishing, and denial-of-service attacks. Between 2012 and 2023, at least six U.S. states have experienced cyberattacks that resulted in access being gained to significant amounts of Medicaid data, including an attack in Texas in 2021 that affected approximately 1.8 million individuals, a data breach in Utah that affected 780,000 Medicaid recipients, and a data breach in South Carolina that affected 228,000 Medicaid recipients.

The penetration tests simulated cyberattacks. While the security controls were found to be generally effective at blocking unsophisticated or limited cyberattacks, improvements are required to prevent more sophisticated attacks and persistent threats. The cybersecurity controls implemented by the nine states – Alabama, Illinois, Maryland, Massachusetts, Michigan, Minnesota, South Carolina, South Dakota, Utah – and Puerto Rico responded to and blocked some of the HHS-OIG’s simulated cyberattacks, but not others. Simulated phishing attempts were also conducted on a selection of employees to determine whether they had received adequate security awareness training.

The most common NIST security controls that were identified as ineffective in most of the audited states were website transmission confidentiality and integrity controls; flaw remediation controls to properly identify, report, and correct software flaws; information input validation controls to verify the validity or properly sanitize the information system input for public-facing systems; and error handling controls to prevent disclosure of information.

The common causes were developers and contractors that were unaware of government standards or industry best practices; the failure to securely configure and patch flaws in a timely manner; the failure to assess all components in MMIS and E&E systems (e.g. third party plug-ins and libraries); infective procedures for testing security controls; and delays in detecting, reporting, and fixing flaws in systems.

HHS-OIG made 27 recommendations to the nine states and Puerto Rico for improving security controls, policies, and procedures. The most common recommendations included: patching outdated servers; improving input sanitization on web servers; enhancing vulnerability detection tools; conducting periodic evaluations of the effectiveness of security controls; updating cryptographic settings; improving vulnerability management strategies; and ensuring server configurations support secure protocols

The post State Medicaid Agencies Need to Improve Security Controls for MMIS and E&E Systems appeared first on The HIPAA Journal.

HHS-OIG Announces 10-Year Exclusions for Companies and Individuals

The Department of Health and Human Services Office of Inspector General (HHS-OIG) maintains an exclusion list of companies and individuals who are not permitted to participate in federal healthcare programs, including indirectly participating by providing goods or services to entities that are billed to federal healthcare programs.

Exclusion is the most severe civil sanction that can be imposed by HHS-OIG and is most commonly due to conviction of a felony or misdemeanor related to a federally funded healthcare program, although individuals and entities can be added to the exclusion list for a variety of reasons. The duration of the exclusion depends on several factors and can range from months to permanent exclusion.

For permissive exclusions, HHS-OIG has discretion over how long the exclusion period lasts. That could be until an individual who has defaulted on a repayment addresses the default, although most permissive exclusions fall in the range of 1 to 3 years. Mandatory exclusions, such as those for misdemeanor and felony convictions, have minimum exclusion periods of 5 or 10 years, although three convictions will result in permanent exclusion.

If an individual is excluded, they are not permitted to work within the healthcare industry for any company that accepts federal funds, which can severely limit work opportunities. Since excluded individuals may still seek employment in the healthcare field, it is vital for employers to regularly check the exclusion list to ensure that new hires can be employed, and also to conduct regular checks of all employed individuals to ensure they can continue to be employed. Employing or continuing to employ an excluded individual risks civil monetary penalties.

HHS-OIG has recently announced new additions to its exclusion list, all of which see the individuals and entities excluded from federally funded healthcare programs for 10 years. In August, HHS-OIG entered into a settlement agreement with Ideal Health Diagnostics, Inc. (Ideal Health) and Svetlana Dizik (Dizik), of Glenview, Illinois, that requires a payment of $227,193.28 in addition to the 10-year exclusion. HHS-OIG alleged that Ideal Health and Dizik solicited and received improper remuneration from Perry Rudich, MD, in exchange for referrals for radiological interpretative services. Ideal Health and Dizik also caused claims to be submitted to Medicare that falsely identified Dr. Rudich as the rendering provider of items and services that he did not perform. Ideal Health and Dizik were not enrolled in Medicare, so they could not bill Medicare for those services themselves or receive payment for those services from Medicare.

In September, HHS-OIG announced 10-year exclusions for Optimum Faith Lab Corp. and its owner, Opal Mullings. Opal Mullings and Optimum had submitted claims for mileage under HCPCS Code P9603 that were improperly inflated, in excess of the actual mileage driven by phlebotomists, not properly prorated, or both. Further, claims were submitted for travel allowance, when only a fingerstick blood draw was performed, when Medicare rules do not permit travel allowance to be claimed for that purpose, and travel allowance was also claimed for laboratory services that were never rendered.

The post HHS-OIG Announces 10-Year Exclusions for Companies and Individuals appeared first on The HIPAA Journal.