Medicare Program Integrity Manual (Pub. 100-08), Ch. 4 § 4.7.2.2
Identifying and Reporting Compromised Medicare Beneficiary
4.7.2.2 – Identifying and Reporting Compromised Medicare Beneficiary
Identifiers (MBIs)
(Rev. 13879; Issued: 07-23-26; Effective: 08-24-26; Implementation: 08-24-26)
For purposes of this chapter, a “compromised MBI” is an MBI that a UPIC determines
has likely been stolen by unauthorized entities or individuals.
UPICs may determine an MBI is compromised in one of two ways:
•
Individual determination
•
Group determination
Compromised MBIs – Individual Determination
UPICs shall make an individual determination of a compromised MBI when they
determine that the beneficiary does not have a verifiable relationship with a provider that
billed, referred, or ordered an item or service on their behalf and a group determination
is not appropriate.
Compromised MBIs – Group Determination
As UCM functionality allows, UPICs may request a group determination of compromised
MBIs when they establish a pattern of beneficiaries not having a verifiable relationship
with a provider that billed, ordered, or referred claims for them. In these cases, groups of
MBIs associated with these providers may be deemed compromised based on evidence
gathered by the UPIC.
To request a group determination of compromised MBIs, UPICs shall document their
rationale for the determination and take appropriate vetting/deconfliction actions in
UCM.