OIG White Paper Tackles DME Fraud

Published: September 7, 2026

AMARILLO, TX – Last month, the OIG issued a White Paper Entitled “The Nation’s Challenge to Combat Durable Medical Equipment Fraud in Medicare.” The White Paper states, in part:

Each year, bad actors defraud Medicare and taxpayers of millions of dollars by billing for durable medical equipment that enrollees do not need or never receive. Despite efforts to combat this fraud, bad actors continually devise new schemes. Bold action is needed to address the underlying problems that allow durable medical equipment fraud to persist.

CMS has recently taken steps to increase its fraud-fighting efforts. For example, CMS has created a new Fraud Defense Operations Center to more proactively identify suspect billing and suspend payments. However, given the extent of durable medical equipment fraud in Medicare and the continuously evolving nature of durable medical equipment fraud schemes, more specific attention is needed to understand and prevent this type of fraud.

 

Want the latest Medtrade and industry news conveniently delivered to your inbox once a week? Subscribe to Medtrade Monday for stories and insights you won’t see anywhere else!

This white paper presents actions that CMS and others can take to stop bad actors from exploiting Medicare… 

Each year, bad actors defraud Medicare and taxpayers of millions of dollars by billing for durable medical equipment that enrollees do not need or never receive. In some instances, they trick Medicare enrollees into sharing their personal information and then use it to bill Medicare. In other instances, they pay physicians to sign fake orders for patients they have never even met. Commonly, these bad actors—including some operating from outside the country—use straw owners to hide their true identities and evade oversight. This fraud must be stopped.

…

The white paper focuses on three key elements that bad actors need to commit DMEPOS fraud: (1) a Medicare-enrolled DMEPOS supplier, (2) a physician order for DMEPOS, and (3) a Medicare enrollee’s identification number. For each of these elements, the paper describes how bad actors commit fraud, identifies existing vulnerabilities, and presents calls to action to address the underlying problems that allow fraud to persist.

Becoming a Medicare – Enrolled DMEPOS Supplier

To commit DMEPOS fraud in Medicare, bad actors must first become a DMEPOS supplier that is enrolled in Medicare. CMS requires that DMEPOS suppliers enroll in Medicare before they are permitted to bill the program. There are two main ways that bad actors become DMEPOS suppliers that are enrolled in Medicare.

  • Open a new DMEPOS supplier business and enroll it in Medicare.
  • Purchase an existing DMEPOS supplier that is already enrolled in Medicare.

Despite current safeguards, bad actors are still able to become Medicare-enrolled DMEPOS suppliers.

  • On-site inspections do not always prevent bad actors from enrolling in Medicare…[The] timing of these on-site inspections can be predictable, allowing bad actors to temporarily stage their facilities to appear compliant.
  • Surety bonds are not effectively protecting the program against fraud…
  • Straw owners are used to evade oversight…
  • Unreported changes of ownership are difficult to detect…
  • Paper enrollment applications can be used to circumvent identity checks. CMS allows DMEPOS suppliers to submit either paper or electronic enrollment applications. Bad actors can use paper applications to avoid certain identity checks that are required to access CMS’s online enrollment system. Additionally, paper applications can conceal the location of the applicant, making it more difficult to track bad actors.
  • DMEPOS suppliers that bill only Medicare Advantage are not required to enroll in Medicare. As a result, these suppliers are not subject to CMS’s screening checks or other enrollment requirements and may pose an increased risk to the program.

CMS has recently taken several steps to prevent bad actors from becoming DMEPOS suppliers that are enrolled in Medicare…These include:

  • Strengthen on-site inspections to prevent bad actors from enrolling in Medicare…This could include additional unannounced on-site inspections to ensure that bad actors cannot predict when site visits will occur.
  • Improve detection of unreported changes of ownership and straw owners. Verifying ownership information can stop bad actors from evading oversight. CMS should work with its Federal partners, such as the Department of Treasury, to identify existing data or collect new data that could improve CMS’s ability to track ownership…
  • Ban suppliers from using paper applications to circumvent oversight…
  • Increase oversight of newly enrolled DMEPOS suppliers…[CMS] should implement a period of enhanced oversight of newly enrolled DMEPOS suppliers and those that recently changed ownership…
  • Reassess and potentially update surety bond requirements to better deter fraud…
  • Take a different approach to enrolling DMEPOS suppliers… Fraudulent DMEPOS suppliers can cluster in geographic areas, such as in parts of a State, certain zip codes, or even specific buildings. In these areas, it appears that there are far more DMEPOS suppliers than necessary to meet enrollee needs. To address this issue, CMS could consider requiring prospective suppliers to demonstrate that its participation in the Medicare program would help meet unmet enrollee needs within an area. Alternatively, CMS could consider denying enrollment to suppliers in areas without unmet enrollee needs…

Obtaining Physician Orders and Submitting Fraudulent Claims for DMEPOS

There are four main ways that bad actors obtain fake physician orders and submit fraudulent claims.

  1. Create fake orders and other documentation…
  2. Pay kickbacks to physicians to order DMEPOS for enrollees…
  3. Scam physicians into unwittingly signing orders for unneeded DMEPOS…
  4. Obtain stolen physician identification numbers…

Despite current safeguards, bad actors still obtain fake physician orders and submit fraudulent claims.

  • Ordering physicians may not know that they are listed on fraudulent DMEPOS claims…
  • Data analysis does not always identify bad actors because fraud schemes constantly evolve…
  • Medical reviews are mainly focused on reducing unintentional billing errors rather than fraud…
  • Fake orders and documentation generated by AI are harder to detect…
  • Payments from secondary payers—such as Medigap plans—may contribute to DMEPOS fraud… [Even] if CMS suspends its payment, secondary payers may continue to pay potentially fraudulent claims…
  • Medicare Advantage organizations are not required to submit information to CMS about the physicians who order DMEPOS…

CMS recently took a number of steps to prevent bad actors from obtaining fake physician orders and submitting fraudulent claims for DMEPOS. However, additional actions are needed. These include:

  • Engage ordering physicians in fraud-fighting efforts…
  • Harness new technologies and analytic tools to better detect and stop payments for fraudulent DMEPOS claims… As a part of these activities, CMS should explore the use of AI and other technologies to assist clinical experts who conduct medical reviews. For example, CMS should explore whether AI-based technology could allow clinical reviewers to identify AI-generated orders and documentation.
  • Enhance the use of payment suspensions…
  • Expand medical reviews to prevent fraud…
  • Work with secondary payers to stop fraudulent billing…
  • Require Medicare Advantage organizations to submit the identification number for the physicians who order DMEPOS…

Obtaining and Using Enrollee Identification Numbers to Fraudulently Bill Medicare

DMEPOS suppliers need enrollee identification numbers to bill Medicare for DMEPOS. There are four main ways bad actors obtain these numbers.

  • Steal enrollee identification numbers. This can occur when health care data systems are breached in a cyberattack.
  • Purchase stolen enrollee identification numbers, e.g., on the dark web or social media platforms.
  • Scam enrollees into unwittingly disclosing their identification numbers.
  • Improperly access online lookup tools that allow providers and suppliers to find enrollees’ identification numbers.

Despite current safeguards, bad actors are able to obtain and use stolen enrollee identification numbers.

  • Numerous cyberattacks have targeted the health care industry and have led to large scale data breaches of enrollee identification numbers.
  • Enrollee lookup tools are improperly accessed by bad actors…
  • Bad actors make unsolicited contact (via phone or text) with enrollees and convince them to disclose their identification numbers or personal information…
  • Social media platforms and the dark web are used to sell stolen identifiers…

CMS recently took several steps to prevent bad actors from obtaining and using stolen enrollee identification numbers…These include:

  • Discontinue or better protect enrollee lookup tools…For example, CMS could restrict how many times a provider or supplier can access the tools each month or take other actions to prevent users from obtaining large batches of identification numbers at one time.
  • Prohibit DMEPOS suppliers from making all types of unsolicited contact with enrollees… [CMS] should seek statutory changes to expressly extend the prohibition on unsolicited telephone contacts to other types of contact (e.g., text, email, and other digital means) and entities that are associated with DMEPOS suppliers, such as marketing agencies and call centers.
  • Partner with social media companies to prevent the sale of enrollee identification numbers on their platforms…
  • Engage Medicare enrollees in the fight against fraud… One option is to develop an enrollee verification program that would allow CMS to contact enrollees and ask them to verify that they received DMEPOS that they needed, either on a routine basis or for unusual or suspicious claims.

Bolder actions for consideration

  • Change the way Medicare protects enrollee identification numbers…

Conclusion
[DMEPOS] fraud continues to be a significant concern in Medicare as bad actors develop new schemes to evade oversight. To address this fraud, it is imperative that CMS and others continue to advance fraud-fighting efforts.

To assist in these efforts, this white paper provides a roadmap and offers actions that CMS and others can take to:

  • Block fraud at the front door by strengthening Medicare enrollment;
  • Catch fake physician orders and claims to stop fueling fraud; and
  • Stop the use of stolen enrollee identification numbers to shut down fraud.

Lessons for DME Suppliers
To quote the author Aldous Huxley, the DME industry is in a “Brave New World.” The DME industry of yesteryear no longer exists. For decades, there was minimal government oversight of the DME industry. As seen by the OIG White Paper, this has been flipped on its head.

To thrive in this new environment, DME suppliers must be hyper vigilant in understanding…and following…the rules imposed on them. Failure to do so can lead to an immediate payment suspension and/or PTAN revocation. This is a huge obstacle for most DME suppliers to overcome.

DME suppliers must have robust compliance programs and must train their employees to understand the documentation and claims submission requirements imposed on the suppliers. Equally as important, DME suppliers must not start down the slippery slope that leads to fraud allegations. The DME supplier needs to be aware of the following maxims: (1) If it appears to be too good to be true, then it is probably not true; (2) It is better to make less money and sleep well at night…than make a lot of money and lie awake at night; and (3) If your brain tells you one thing, and your stomach tells you something else, ignore your brain and trust your stomach.

Jeffrey S. Baird, JD, is chairman of the Health Care Group at Brown & Fortunato, PC, a law firm based in Texas with a national healthcare practice. He represents pharmacies, infusion companies, HME companies, manufacturers, and other healthcare providers throughout the United States. Baird is Board Certified in Health Law by the Texas Board of Legal Specialization and can be reached at (806) 345-6320 or [email protected].