The U.S. Department of Health & Human Services’ Office of the Inspector General (OIG) has published a white paper describing how durable medical equipment (DME) fraud occurs and how the Centers for Medicare & Medicaid Services (CMS) is responding.
The report — White Paper: The Nation’s Challenge to Combat Durable Medical Equipment Fraud in Medicare — was publicly published Aug. 20.
“Each year, bad actors defraud Medicare and taxpayers of millions of dollars by billing for durable medical equipment that enrollees do not need or never receive,” the paper said. “Despite efforts to combat this fraud, bad actors continually devise new schemes. Bold action is needed to address the underlying problems that allow durable medical equipment fraud to persist.”
Three components of fraud
The OIG focused on “three elements that bad actors need to commit fraud: a Medicare-enrolled supplier, a physician order and an enrollee identification number.”
The white paper noted that Medicare DME fraud requires a DME provider who is enrolled to bill Medicare. “Bad actors are evading enrollment safeguards, e.g., by hiding the owner’s true identity,” the OIG said. To “block fraud at the front door,” the white paper recommended “strengthening Medicare enrollment,” to include improving detection of unreported changes of ownership and straw owners, as well as increasing oversight of newly enrolled suppliers.
A straw owner is an official owner according to official documentation, but one who takes orders from another entity.
The second element of fraud are physician orders: “Bad actors are creating — or paying for — fake physician orders and using them to submit fraudulent claims,” the OIG report said. To prevent fraud, the OIG recommended enlisting physicians to participate in fraud-fighting efforts, and using new technologies and tools “to better detect and stop payments for fraudulent claims.”
The final fraud element is beneficiary identification numbers, which are being stolen and used or stolen and sold for criminal use.
The OIG suggested partnering “with social media companies to prevent the sale of enrollee numbers on their platforms” and also changing “the way Medicare protects enrollee identification numbers.”
CMS’s antifraud actions
To combat fraud, “CMS is working with the Office of Inspector General through its new Fraud Defense Operations Center to more proactively identify suspect billing and suspend payments,” the white paper said. “CMS has also instituted a nationwide temporary moratorium on Medicare enrollment of new DMEPOS [durable medical equipment, prosthetics, orthotics and supplies] suppliers while it considers further safeguards.”
The paper included examples of fraudulent actions, including Operation Gold Rush: “A transnational criminal organization is accused of running a complex DMEPOS fraud scheme that billed Medicare for more than $10 billion. The group used straw owners to hide their true identities while buying dozens of DMEPOS suppliers that were already allowed to bill Medicare.
“Using stolen enrollee information, they then submitted huge volumes of false claims for medical equipment that was never ordered by physicians and never provided to patients.”
In another scheme, known as Operation Brace Yourself, Medicare beneficiaries who saw ads for free braces contacted overseas call centers, who “then pressured them into accepting multiple unnecessary items.” From there, calls were routed to telemedicine physicians “who ordered unneeded braces, and unscrupulous DMEPOS companies used those orders to bill Medicare.”
The paper said on-site inspections “do not always prevent bad actors from enrolling in Medicare” because those inspections “focus on whether suppliers meet specific standards — such as posting their hours and having a working business phone number.”
The report added that current surety bond requirements — typically mandating that a supplier purchase a $50,000 surety bond that costs about $1500 — “are not effectively protecting the program against fraud.”
CMS can find it difficult to detect changes in supplier business ownership, and the OIG said bad actors can use paper enrollment applications “to avoid certain identity checks that are required to access CMS’s online enrollment system” while also making it difficult for CMS to determine the applicant’s location.
The report added that suppliers who only bill Medicare Advantage plans “are not required to enroll in Medicare. As a result, these suppliers are not subject to CMS’s screening checks or other enrollment requirements and may pose an increased risk to the program.”
The OIG suggested CMS consider “alternative approaches” to enrolling DME suppliers, such as requiring prospective suppliers “to demonstrate that its participation in the Medicare program would help meet unmet enrollee needs within an area. Alternatively, CMS could consider denying enrollment to suppliers in areas without unmet enrollee needs.”
The white paper “is based on expertise from past OIG investigations, audits and evaluations,” and also was supported by “structured interviews with CMS staff, CMS contractors and Medicare Advantage organizations.”
The OIG said it also “conducted reviews of key documents, relevant regulations and CMS guidance.”