Medicare Program Integrity Manual (Pub. 100-08), Ch. 4 § 4.7.2.1
Provider Identity Theft Investigations and Victimized Provider
4.7.2.1 – Provider Identity Theft Investigations and Victimized Provider
Waiver of Liability Process
(Rev. 13879; Issued: 07-23-26; Effective: 08-24-26; Implementation: 08-24-26)
For purposes of this chapter, a “compromised NPI” is a provider/supplier number that
has been used by unauthorized entities or individuals to submit claims to, i.e., bill, the
Medicare program.
The UPICs shall investigate the alleged theft of provider identities, and report validated
compromised NPIs into the UCM Compromised Number Records module, in accordance
with the applicable instruction and guidance documents (Of note, the instruction and
guidance documents are located in the “Job Aids” and “Release Notes” section of the
UCM Documentation Storage site. These documents are updated each time
updates/enhancements occur.). An example of provider identity theft may include a
provider’s identity having been stolen and used to establish a new Medicare enrollment
or a new billing number (reassignment) under an existing Medicare enrollment, or
updating a current Medicare provider identification number with a different electronic
funds transfer (EFT) payment account causing inappropriate Medicare payments to
unknown person(s) and potential Medicare overpayment and eventually, U.S.
Department of Treasury (UST) debt issued to the victimized provider.
The UPICs shall discuss the identity theft case with the BFL. If claims are still being
submitted and Medicare payments are being made, the UPIC should pursue strategies to
prevent likely overpayments from being disbursed, such as prepayment reviews, auto-
denial edits, Do Not Forward (DNF) requests, or immediate payment suspensions. The
purpose of these administrative actions is to stop the payments. The UPICs are not
authorized to request the MAC to write-off any overpayments related to the ID theft.
Prior to any enrollment actions, the UPIC should be aware of the suspected victim’s
reassignments and consider the effect of Medicare enrollment enforcement actions on
the alleged ID theft victim’s current employments.
If an actual financial harm exists as a result of the ID theft (i.e., existence of Medicare
debt or overpayment determination), the UPIC will follow the Victimized Provider
Project (VPP) procedures, which include the following:
• At the point in which a UPIC begins to investigate provider ID theft
complaints and incurred debt, it sends a letter acknowledging receipt of the
complaint, informing the provider that CMS is investigating the complaint and
reviewing materials submitted, and designating a VPP point of contact at the
UPIC (IOM Pub. #100-08; Exhibit 8 – Letter 1);
• The next steps in this process include, but may not be limited to, the following:
• Check if the case in question is in the UCM system. Vet
the provider(s) with the DHHS - OIG or other
appropriate LE agency to ensure that the contractor’s
investigative process will not interfere with
prosecution;
• A VPP case package must then be completed by the
UPIC using the templates provided in the VPP
information packet;
• Describe the case and how the provider’s ID was stolen or
compromised. List all overpayment(s) for which the provider is being
held liable. Clearly indicate those paid amounts that are in DNF
and/or on payment suspension status, and the amounts that were paid
with an actual check or electronic transfer to the fraudulent bank
account;
• Provide legitimate and compromised/stolen 855 forms with provider
enrollment and reassignment of benefits information in order to verify
legitimate PTAN(s)/NPI(s) and identify the fraudulent ones;
• Get signed provider victim attestation statement(s) about the ID theft
from the provider(s)/supplier(s).
• Provide a police report from the alleged victim provider or any law
enforcement documentation;
• Provide financial background information, such as
•
IRS Form 1099 or W-2; and
•
Overpayment requests/debt collection notices.
• Include any trial, DOJ and OIG documents like OIG proffers,
indictment, judgments and sentencing documents; and
• Based on the information gathered and the investigation conducted, the
UPICs will state their recommendation as part of the package and
provide the reason for the recommendation. Two recommendations are
possible:
• Hold provider harmless and rescind provider
of federal ID theft case-related debt; OR
• Hold provider liable for debt.
The UPIC will submit the complete VPP packet to the CMS CPI VPP team. In ID theft
cases in which the victimized providers are located in multiple states and served by
different UPICs, the UPIC jurisdiction in which the perpetrator’s trial was located will
be the lead UPIC that will coordinate with the other UPICs and submit a completed
VPP packet to the CMS CPI VPP team.
The VPP team will validate and remediate all facts and information submitted by the
UPIC. Part of the VPP team review may involve consultation with the HHS Office of
General Counsel. This consultation may include, but may not be limited to,
consideration of supporting documentation or lack thereof to support a decision that the
provider is an actual victim of ID theft as well as compliance with federal statutes and
regulations related to ID theft policies, debt collection and recall of overpayments.
The VPP team will make a final determination if the alleged ID theft victim is a true
victim and approve a rescindment of Medicare overpayments reported in the name of the
confirmed ID theft victim.
When calculating the actual overpayments related to the fraudulent claims under each
provider victim, there may be situations in which discrepancies exist between LE and
contractor loss calculation data. In these situations, the final figures used in making
overpayment determinations should come from MAC data on amounts paid out in the
name of the victimized providers using the cleared payments transmitted to the
fraudulent bank accounts established in the DOJ case.
Once a final decision is made by the VPP team, the UPIC or Lead UPIC, as
appropriate, will be informed.
If the provider victim is determined to be a true victim of ID theft, the UPIC will send
out a letter using the template in the IOM Pub. #100-08 Exhibits chapter informing the
provider of the favorable decision and that the assessed overpayment against the victim
will be rescinded ((IOM Pub. #100-08; Exhibit 8 – Letter 2). This decision shall then
flow through the UPIC to the MAC for a recall of the associated debt. (NOTE: The
MAC’s instructions for processing providers’ debts that have been confirmed as identity
theft are found in the Medicare Financial Management Manual Chapter 4, Section 110 –
Confirmed Identity Theft). The MAC shall follow the process for making adjustments to
the claims system and recall the debt registered under the victimized provider from the
US Department of Treasury.
If the decision is not positive (i.e. ID theft is not confirmed), the UPIC shall correspond
directly with the provider to inform him/her that CMS did not have sufficient information
to confirm that identity theft has occurred. The UPIC shall send Letter 3 from the IOM
Pub. #100-08 Exhibits chapter to the provider with a copy to the MAC.