Published on:

Medicare-certified hospice providers are facing heightened regulatory oversight. In response to ongoing concerns about hospice compliance, as well as fraud, waste, and abuse within the hospice industry, both the Centers for Medicare & Medicaid Services (“CMS”) and the Department of Health and Human Services Office of Inspector General (“OIG”) have expanded their use of audits, investigations, and enforcement actions targeting hospice providers. Among these enforcement tools are Provisional Period of Enhanced Oversight (“PPEO”) audits, which apply to certain Medicare-enrolled hospice agencies. Providers should recognize that a PPEO audit can carry significant consequences, even where the perceived compliance issues appear relatively minor.

CMS introduced PPEO audits to address concerns surrounding hospice program integrity and regulatory compliance. Under the PPEO initiative, beginning in mid-2023, CMS has required audits of all “newly enrolled” hospice providers located in Arizona, California, Nevada, and Texas. Georgia and Ohio were added in late 2025. For purposes of the program, the term “newly enrolled” extends beyond providers entering the Medicare program for the first time. It also includes hospices that have undergone a Change of Ownership (“CHOW”), as defined by Medicare regulations, providers that have experienced a 100% ownership transfer, and agencies reactivating Medicare enrollment after a period of deactivation.

PPEO audits are sometimes likened to Targeted Probe and Educate (“TPE”) reviews because both processes may involve multiple rounds of claim review during which providers can receive feedback and, in some cases, an opportunity to correct identified deficiencies. That comparison, however, is limited, and in practice the two review processes differ substantially. TPE audits typically involve three rounds of review, and occasionally a fourth. CMS guidance requires the reviewing contractor to provide education to the provider and to allow time between review rounds so the provider can implement corrective measures and improve compliance. In addition, providers generally are not referred to CMS for administrative sanctions unless they fail three consecutive rounds of review by demonstrating persistently high error rates throughout the TPE process. Although TPE audits can ultimately result in revocation of Medicare billing privileges, that outcome generally occurs only after repeated unsuccessful review cycles.

Published on:

In the recently published 2027 Home Health PPS proposed rule, CMS proposed several significant expansions of its authority to revoke Medicare billing privileges.

CMS proposed two new bases on which it would be permitted to revoke Medicare billing privileges. First, CMS proposed that it be permitted to revoke a provider’s or supplier’s Medicare enrollment if CMS “deems the enrollment as presenting a high risk of fraud, waste, or abuse due to the provider’s or supplier’s location within a limited geographic area that has an excessive number of providers and suppliers.” This proposal was a direct response to recent media reports regarding large numbers of providers registered or operating at the same address or building. However, the extremely broad and vague authority that CMS seeks is concerning for providers, as CMS declined to limit what is meant by “high risk,” “excessive number,” or “limited geographic areas” and also stated that an actual showing of fraud would not be required. This expansion would effectively permit CMS to revoke the Medicare enrollment of any provider, anywhere, anytime, and without a showing of misconduct by the provider.

Second, CMS proposed that it be permitted to revoke Medicare enrollments where a provider or supplier, or any owner, manger, officer, or director, is convicted of a federal or state misdemeanor related to sexual assault or financial misconduct within the past 10 years that CMS deems detrimental to the best interests of the Medicare program and its beneficiaries. CMS has long had the authority to revoke for felonies, but has struggled to define how it should address misdemeanor convictions. A similar, though broader, proposal in 2024 was never implemented. This more limited proposal would permit CMS to revoked Medicare enrollment based on crimes that are plainly harmful to patients and/or the Medicare program, but that are simply not categorized as felonies.

Published on:

For healthcare providers enrolled in Medicare, a claims audit can present significant operational and financial challenges. When an audit results in denied claims, the appeals process often becomes lengthy, with cases taking months—or even years—to reach a final resolution. Successfully navigating each stage requires careful planning, strategic decision-making, and close attention to procedural deadlines.

Most Medicare audits begin with a request for medical records from a Medicare contractor. From the outset, providers should determine the purpose and scope of the review. Identifying the contractor conducting the audit—whether a Medicare Administrative Contractor (MAC), Unified Program Integrity Contractor (UPIC), Recovery Audit Contractor (RAC), or Supplemental Medical Review Contractor (SMRC)—can offer valuable insight into the government’s objectives. It is equally important to understand the type of audit involved. Is the review occurring before or after payment? Is it part of a Targeted Probe and Educate (TPE) initiative, a Comprehensive Error Rate Testing (CERT) review, or a Provisional Period of Enhanced Oversight (PPEO) audit? Providers should also evaluate whether statistical sampling or extrapolation may be part of the review.

The provider’s own circumstances should also factor into a response strategy. Previous audit activity, recent ownership changes, or situations where records are maintained by another organization may all influence how the audit should be handled. Depending on the issues presented and the potential exposure, providers may choose to supplement the record with additional documentation, obtain an independent clinical review, communicate directly with the auditing contractor, or prepare a comprehensive legal response. In lower-risk situations, however, submitting the requested records and waiting for the contractor’s determination may be the most appropriate approach.

Published on:

The HHS Office of Inspector General (OIG) recently updated its work plan to announce two new initiatives directed towards clinical laboratories billing Medicare for laboratory tests. The OIG work plan includes the various projects, audits, evaluations, and reviews that OIG is planning or that are currently underway. Medicare providers often experience the downstream effects of OIG projects or are directly the subject of OIG projects, and should therefore be aware of OIG’s enforcement priorities.

First, OIG intends to review trends and vulnerabilities in genetic tests covered under Medicare Part B. OIG noted the steady increase in Medicare expenditures on genetic tests, as well as the higher average per-test payment amount of these tests when compared to other laboratory tests under Part B. OIG asserted that it had identified genetic testing fraud schemes involving deceptive telemarketing campaigns and kickbacks. Pursuant to this project, OIG will examine avenues for strengthening oversight of genetic tests covered under Part B, including identifying tests that may be vulnerable to fraud, waste, and abuse; assessing trends among laboratory test providers; and examining whether geographic variations exist, particularly between jurisdictions that do and do not participate in the Molecular Diagnostic Services Program.

Second, OIG intends to review Medicare payments to providers for some expanded laboratory panels. OIG noted that expanded panels (those that can detect six or more pathogens) result in higher Medicare payments than targeted panels (those that can detect up to five pathogens). OIG stated it has concerns that providers have been administering expanded laboratory panels when targeted laboratory panels would be sufficient, resulting in significantly higher Medicare payments to those providers. OIG intends to determine whether Medicare has paid providers for some selected expanded panels that are not medically necessary, do not meet Local Coverage Determination (LCD) requirements, or otherwise do not meet Medicare requirements.

Published on:

On December 31, 2025, the Drug Enforcement Administration (DEA) released a fourth temporary rule extending certain controlled substance prescribing flexibilities through December 31, 2026. The Rule creates an exception to the 2008 Ryan Haight Act, which requires providers to conduct an in-person examination before prescribing Schedule II–V controlled substances. This temporary rule immediately follows a November 2024 extension that expired on December 31, 2025. The extension of telehealth flexibilities, which policymakers originally invoked in response to the COVID-19 public health emergency, prevents an abrupt end to telehealth services for providers and patients. The Rule allows patients in rural and underserved communities, the elderly, and patients with mobility challenges to maintain continuous, uninterrupted access to care and necessary controlled medications without an in-person visit.

Regulators have taken several steps to make portions of the telehealth flexibilities permanent. In March 2023, the DEA and the Substance Abuse and Mental Health Services Administration (SAMHSA) issued two notices of proposed rulemaking: “Telemedicine Prescribing of Controlled Substances When the Practitioner and the Patient Have Not Had a Prior In-Person Medical Evaluation” and “Expansion of Induction of Buprenorphine via Telemedicine Encounter.” Together, these notices generated more than 38,000 comments, many of which recommended varying degrees of change.

On January 17, 2025, the DEA published the “Special Registrations for Telemedicine and Limited State Telemedicine Registrations” Notice of Proposed Rulemaking, which proposed a framework for a Special Registration for Telemedicine. Under this proposal, providers who continue to prescribe controlled medications without an initial in-person evaluation would need to comply with additional registration, reporting, and recordkeeping requirements. The DEA received an additional 6,000 comments in response.

Published on:

Medicare participation offers essential opportunities for providers and suppliers, but it also comes with a framework of regulatory responsibilities and administrative risks. One area that continues to generate questions, as well as significant operational impacts, is Medicare enrollment revocation. While most organizations are familiar with the concept in broad terms, the underlying causes, processes, and potential consequences remain complex. A clearer understanding of the general landscape can help healthcare providers and suppliers maintain compliance and reduce unexpected disruptions.

At its core, a Medicare revocation occurs when the Centers for Medicare & Medicaid Services (CMS) removes a provider or supplier’s enrollment and billing privileges. This action typically arises from situations indicating noncompliance with program requirements or the appearance thereof. In some cases, these may relate to issues such as improper reporting, operational concerns, or other regulatory or medical review findings that signal a need for CMS to reassess a provider’s or supplier’s continued participation. In other cases, a provider’s failure to respond to medical records requests or errors by a contractor can give rise to the appearance that the provider had engaged in conduct that would warrant a revocation.

The revocation process generally begins when CMS or a Medicare Administrative Contractor (MAC) identifies a potential issue. Providers and suppliers are notified in writing and given information about the basis for the action. Although the communication outlines key details, the language can often feel broad or vague, particularly because revocation authorities cover a wide range of scenarios. Regardless of the particular circumstances, receiving a revocation notice should prompt immediate attention and internal review.

Published on:

In a move aimed at addressing the persistent challenge of high healthcare spending, the Centers for Medicare & Medicaid Services (CMS) recently launched a new payment and oversight model called WISeR, short for “Wasteful and Inappropriate Service Reduction.” Set to begin in January 2026 and run through 2031, WISeR is designed to use artificial intelligence (AI) to identify and reduce the provision of services that Medicare deems unnecessary, duplicative, or low value. While its goals are familiar, the model marks a shift in how CMS is approaching prior authorization, technology use, and provider oversight.

For healthcare providers, WISeR represents both a policy change and a shift in operational workflow, especially for those practicing in the six participating states: Arizona, New Jersey, Ohio, Oklahoma, Texas, and Washington. Although the model is technically focused on a limited number of outpatient services, including certain spinal procedures, wound care treatments, and pain management interventions, its implications could be far-reaching.

WISeR does not alter Medicare’s coverage or payment rules. Instead, it changes the process through which specific services are reviewed before payment is made. Providers in participating states will face two main options: they can submit prior authorization requests through CMS-approved technology vendors or have claims for selected services reviewed through a more rigorous prepayment review process.

Published on:

For healthcare providers participating in the Medicare program, facing a claims audit can be both challenging and time-consuming. Denials are common during these audits, and when they occur, the appeals process can stretch over months or even years. Each step requires careful strategy and timely action.

Typically, a Medicare audit is initiated when a Medicare contractor requests medical records from a provider. At this early stage, it’s crucial to understand the context of the request. Identifying the type of contractor involved, whether it’s a Medicare Administrative Contractor (MAC), Unified Program Integrity Contractor (UPIC), Recovery Audit Contractor (RAC), or Supplemental Medical Review Contractor (SMRC), can provide important insight into what kind of review is being conducted. The nature of the review itself also matters: is it a pre-payment or post-payment audit? Is it part of a Targeted Probe and Educate (TPE) program, a Comprehensive Error Rate Testing (CERT) audit, or a Potential Payment Error Opportunity (PPEO) initiative? Is there a likelihood that the audit includes statistical extrapolation?

The provider’s own history and operational context can also affect the review. For instance, has the provider faced similar audits recently? Was there a recent ownership transfer? Are any necessary records held by another entity? These details may guide the provider’s next steps. Depending on the scope and risk level of the audit, providers might take proactive measures to support their claims. This could include submitting additional documentation, hiring a clinical reviewer to evaluate the claims, engaging directly with the contractor, or preparing a detailed legal response. In other situations, simply submitting the requested records and awaiting a decision may be the most prudent course.

Published on:

The HHS Office of Inspector General (OIG) recently issued several new work plan items outlining audits it intends to perform and initiative it intends to undertake. OIG investigations and initiatives can concern activities by federal healthcare programs like Medicare and Medicaid, their contractors, and participating providers. However, it is often providers who experience the downstream impacts of OIG initiatives. Healthcare providers should be aware of OIG’s enforcement priorities.

First, OIG intends to review Medicaid nonemergency medical transportation services. OIG noted that such services can pose a significant risk of fraud, waste, and abuse in Medicaid and that past OIG work has identified significant vulnerabilities in State and Federal efforts to reduce fraud, waste, and abuse involving nonemergency medical transportation in Medicaid. It appears that OIG intends to conduct targeted reviews of certain nonemergency medical transportation providers. Such providers should be prepared for increased levels of scrutiny from OIG and their local Medicaid programs.

Second, OIG intends to produce a white paper regarding fraud, waste, and abuse related to durable medical equipment (DME) in Medicare. DME has long been an area of concern for the Medicare program and federal law enforcement and OIG noted that that recent cases demonstrate that fraudsters continue to target DMEPOS billing and have developed new schemes. OIG intends to build on its extensive experience with DME fraud and provide further information about the nature of DMEPOS fraud in Medicare, key program integrity vulnerabilities, and potential actions to reduce fraud, waste, and abuse.

Published on:

Entities operating in the healthcare industry, especially those that submit claims to government-funded programs like Medicare or Medicaid, must navigate a complex landscape of laws designed to prevent fraud, waste, and abuse. The most critical federal statutes in this area include the Physician Self-Referral Law (commonly known as the “Stark Law”), the Anti-Kickback Statute (AKS), and the Eliminating Kickbacks in Recovery Act (EKRA). Even seemingly straightforward business relationships can demand intricate legal analysis when these laws are involved.

The Stark Law (42 U.S.C. § 1395nn) restricts physicians from referring patients for certain healthcare services, referred to as “designated health services,” to entities with which they or their immediate family members have a financial relationship, unless a specific exception applies. These financial ties can take various forms, including employment arrangements, compensation agreements, or investment interests. Notably, the Stark Law doesn’t cover all services under Medicare or Medicaid, only those specifically listed as designated health services. Although the law includes a number of exceptions, such as those for in-office ancillary services or arrangements based on fair market value, each exception has detailed criteria that must be satisfied fully for it to be valid.

Similarly, the Anti-Kickback Statute (42 U.S.C. § 1320a-7b(b)) prohibits the offer, payment, solicitation, or receipt of anything of value in exchange for referrals or to induce business for services reimbursable by federal healthcare programs. The AKS has a broader scope than the Stark Law, covering any service billed to these federal programs, and defines “remuneration” broadly to include cash, gifts, discounts, or anything else of value. The statute is accompanied by a set of “safe harbors,” regulatory provisions that protect certain arrangements from enforcement actions if all specified conditions are met.

Contact Information