Medicare Program Integrity Manual (Pub. 100-08), Ch. 4 § 4.7.2.1

Provider Identity Theft Investigations and Victimized Provider

Last amended: 2026Year: 2026Length: 1,133 wordsOfficial source
4.7.2.1 – Provider Identity Theft Investigations and Victimized Provider Waiver of Liability Process (Rev. 13879; Issued: 07-23-26; Effective: 08-24-26; Implementation: 08-24-26) For purposes of this chapter, a “compromised NPI” is a provider/supplier number that has been used by unauthorized entities or individuals to submit claims to, i.e., bill, the Medicare program. The UPICs shall investigate the alleged theft of provider identities, and report validated compromised NPIs into the UCM Compromised Number Records module, in accordance with the applicable instruction and guidance documents (Of note, the instruction and guidance documents are located in the “Job Aids” and “Release Notes” section of the UCM Documentation Storage site. These documents are updated each time updates/enhancements occur.). An example of provider identity theft may include a provider’s identity having been stolen and used to establish a new Medicare enrollment or a new billing number (reassignment) under an existing Medicare enrollment, or updating a current Medicare provider identification number with a different electronic funds transfer (EFT) payment account causing inappropriate Medicare payments to unknown person(s) and potential Medicare overpayment and eventually, U.S. Department of Treasury (UST) debt issued to the victimized provider. The UPICs shall discuss the identity theft case with the BFL. If claims are still being submitted and Medicare payments are being made, the UPIC should pursue strategies to prevent likely overpayments from being disbursed, such as prepayment reviews, auto- denial edits, Do Not Forward (DNF) requests, or immediate payment suspensions. The purpose of these administrative actions is to stop the payments. The UPICs are not authorized to request the MAC to write-off any overpayments related to the ID theft. Prior to any enrollment actions, the UPIC should be aware of the suspected victim’s reassignments and consider the effect of Medicare enrollment enforcement actions on the alleged ID theft victim’s current employments. If an actual financial harm exists as a result of the ID theft (i.e., existence of Medicare debt or overpayment determination), the UPIC will follow the Victimized Provider Project (VPP) procedures, which include the following: • At the point in which a UPIC begins to investigate provider ID theft complaints and incurred debt, it sends a letter acknowledging receipt of the complaint, informing the provider that CMS is investigating the complaint and reviewing materials submitted, and designating a VPP point of contact at the UPIC (IOM Pub. #100-08; Exhibit 8 – Letter 1); • The next steps in this process include, but may not be limited to, the following: • Check if the case in question is in the UCM system. Vet the provider(s) with the DHHS - OIG or other appropriate LE agency to ensure that the contractor’s investigative process will not interfere with prosecution; • A VPP case package must then be completed by the UPIC using the templates provided in the VPP information packet; • Describe the case and how the provider’s ID was stolen or compromised. List all overpayment(s) for which the provider is being held liable. Clearly indicate those paid amounts that are in DNF and/or on payment suspension status, and the amounts that were paid with an actual check or electronic transfer to the fraudulent bank account; • Provide legitimate and compromised/stolen 855 forms with provider enrollment and reassignment of benefits information in order to verify legitimate PTAN(s)/NPI(s) and identify the fraudulent ones; • Get signed provider victim attestation statement(s) about the ID theft from the provider(s)/supplier(s). • Provide a police report from the alleged victim provider or any law enforcement documentation; • Provide financial background information, such as • IRS Form 1099 or W-2; and • Overpayment requests/debt collection notices. • Include any trial, DOJ and OIG documents like OIG proffers, indictment, judgments and sentencing documents; and • Based on the information gathered and the investigation conducted, the UPICs will state their recommendation as part of the package and provide the reason for the recommendation. Two recommendations are possible: • Hold provider harmless and rescind provider of federal ID theft case-related debt; OR • Hold provider liable for debt. The UPIC will submit the complete VPP packet to the CMS CPI VPP team. In ID theft cases in which the victimized providers are located in multiple states and served by different UPICs, the UPIC jurisdiction in which the perpetrator’s trial was located will be the lead UPIC that will coordinate with the other UPICs and submit a completed VPP packet to the CMS CPI VPP team. The VPP team will validate and remediate all facts and information submitted by the UPIC. Part of the VPP team review may involve consultation with the HHS Office of General Counsel. This consultation may include, but may not be limited to, consideration of supporting documentation or lack thereof to support a decision that the provider is an actual victim of ID theft as well as compliance with federal statutes and regulations related to ID theft policies, debt collection and recall of overpayments. The VPP team will make a final determination if the alleged ID theft victim is a true victim and approve a rescindment of Medicare overpayments reported in the name of the confirmed ID theft victim. When calculating the actual overpayments related to the fraudulent claims under each provider victim, there may be situations in which discrepancies exist between LE and contractor loss calculation data. In these situations, the final figures used in making overpayment determinations should come from MAC data on amounts paid out in the name of the victimized providers using the cleared payments transmitted to the fraudulent bank accounts established in the DOJ case. Once a final decision is made by the VPP team, the UPIC or Lead UPIC, as appropriate, will be informed. If the provider victim is determined to be a true victim of ID theft, the UPIC will send out a letter using the template in the IOM Pub. #100-08 Exhibits chapter informing the provider of the favorable decision and that the assessed overpayment against the victim will be rescinded ((IOM Pub. #100-08; Exhibit 8 – Letter 2). This decision shall then flow through the UPIC to the MAC for a recall of the associated debt. (NOTE: The MAC’s instructions for processing providers’ debts that have been confirmed as identity theft are found in the Medicare Financial Management Manual Chapter 4, Section 110 – Confirmed Identity Theft). The MAC shall follow the process for making adjustments to the claims system and recall the debt registered under the victimized provider from the US Department of Treasury. If the decision is not positive (i.e. ID theft is not confirmed), the UPIC shall correspond directly with the provider to inform him/her that CMS did not have sufficient information to confirm that identity theft has occurred. The UPIC shall send Letter 3 from the IOM Pub. #100-08 Exhibits chapter to the provider with a copy to the MAC.
Medicare Program Integrity Manual (Pub. 100-08), Ch. 4 § 4.7.2.1: Provider Identity Theft Investigations and Victimized Provider | Justis AI