Medicare Fraud Enforcement Now Runs on Data. Is Your Organization Ready?
Originally published on October 6, 2026
Over two days in December 2025, one Florida medical supply company submitted roughly $18.4 million in Medicare claims for catheters, and none of that money reached the supplier. That company was one of 11 that CMS barred on September 8, 2026, after linking them to more than $3.4 billion in suspected Medicare fraud billed across 2025 and 2026. The dollar figure grabs headlines, but the bigger story is how CMS caught them: advanced data analytics that spot unusual billing patterns and stop payments before they go out. For healthcare organizations that would never commit fraud, that detection engine is the part worth understanding, because it doesn’t check intent before it flags an outlier.
What the $3.4 Billion Medical Equipment Fraud Case Revealed
The 11 durable medical equipment, prosthetics, orthotics and supplies (DMEPOS) suppliers shared a familiar profile. According to the CMS announcement of the supplier crackdown, none had submitted claims before 2025, all billed for beneficiaries who had already died and several billed for equipment patients never requested or received. In one Texas case, beneficiaries told investigators they didn’t know the ordering providers, had never heard of the company and didn’t need the orthotics.
None of this is sophisticated. Billing for deceased patients is about as basic as fraud gets. What’s changed is the speed of detection. CMS used its payment-suspension authority to stop nearly $24 million in claims from two suppliers before the money left the agency, and it placed the suppliers on the Medicare Preclusion List, cutting them off from Medicare Advantage (MA) and Part D payments.
CMS Administrator Dr. Mehmet Oz described the approach as using analytics “to identify fraud networks and stop suspicious payments before the check clears.” That last phrase signals a move away from pay-and-chase recovery and toward prevention. For every organization that bills federal programs, it means review now happens much closer to the moment a claim is submitted.
Healthcare Fraud Analytics Are Now the Front Line of Enforcement
The CMS action didn’t happen in isolation. In June 2026, the Department of Justice announced its 2026 National Health Care Fraud Takedown, charging 455 defendants, including 90 doctors and other licensed professionals, in schemes tied to more than $6.5 billion in alleged false claims. Fifty state Medicaid Fraud Control Units took part, the most in the department’s history, and the action produced a record number of Medicaid fraud charges.
Data analytics drove much of that work. DOJ credited its Health Care Fraud Unit’s Data Analytics Team with spotting a spike in payments for wound allografts that led to prosecutions. CMS suspended 1,079 providers and revoked billing privileges for 1,403 more as part of the effort, and DOJ announced new data-sharing agreements with CMS, the Department of Homeland Security and the Federal Trade Commission to support analytics in future investigations.
Put simply, Medicare and Medicaid claims are being watched by systems built to find statistical outliers. These systems compare providers against peers, against their own history and against beneficiary records like dates of death. They’re very good at finding things that look wrong. They’re far less able to tell the difference between fraud and a legitimate change that simply looks unusual.
Why “We Don’t Commit Fraud” Isn’t a Compliance Strategy
Here’s the uncomfortable truth for honest providers: an algorithm doesn’t read your mission statement. A practice that adds a service line, hires a high-volume provider or signs with a new supplier can produce a billing pattern that resembles the early stages of a scheme. The data will flag it either way. What happens next depends on how quickly you can explain and document the change.
Consider the Texas case again. Beneficiaries said they didn’t know the ordering providers listed on their claims, which raises a question every practice should ask: whose claims carry your providers’ names? If a supplier you’ve never worked with is billing under your physicians’ NPIs and later lands on the Preclusion List, your organization is now part of the data trail, and you may face questions you aren’t ready to answer.
The financial stakes are real even without wrongdoing. A payment suspension can freeze cash flow for months, and overpayment findings from a small statistical sample can be projected across a much larger set of claims. Organizations with thin margins, including Federally Qualified Health Centers and community clinics, have the least room to absorb that kind of disruption.
Medicare Advantage Billing Is No Longer a Safe Harbor for Bad Actors
One detail in the CMS release deserves more attention than it got. Four of the 11 suppliers had already been revoked from Original Medicare and simply started billing Medicare Advantage plans instead. That move worked for a while because MA plans screen and pay suppliers separately from traditional Medicare.
HHS-OIG has flagged the same weakness. In a 2026 issue brief on preventing durable medical equipment fraud in Medicare Advantage, OIG noted that MA organizations and CMS take steps to screen suppliers, but gaps in that screening can be exploited. The Preclusion List action shows CMS closing that door, and MA plans have every reason to follow with tighter vendor screening, more prepayment review and more documentation requests.
For providers, MA revenue now deserves the same compliance attention as fee-for-service revenue. If your organization treats MA claims as the plan’s problem, expect that assumption to be tested. Contracts, credentialing files and clinical documentation should hold up whether the payer is CMS or a private plan.
Five Controls That Belong in Every Fraud Risk Assessment
The organizations best positioned for this environment will see their own data before regulators do. Practical steps include:
- Run your own billing analytics. Compare claim volume by code, provider, location and payer against prior periods, and look into any spike you can’t explain with a clear business reason.
- Watch your ordering and referring activity. Review claims that list your providers as ordering or referring, especially for DME, labs and imaging, and follow up on any supplier you don’t recognize.
- Screen vendors and referral partners on a schedule. Check suppliers and partners against the OIG exclusion list and the CMS Preclusion List before contracting and at regular intervals afterward, not just at onboarding.
- Tighten revenue cycle controls. Clear documentation standards, medical necessity checks and separation between staff who submit claims and staff who post payments close the gaps analytics are designed to find.
- Plan your response before you need it. A periodic, independent review of claims patterns, vendor relationships and internal controls, paired with a playbook for documentation requests or payment suspensions, turns a surprise into a process.
None of these steps require you to assume the worst about your team. They’re about making sure your data tells an accurate story, because someone else is already reading it. James Moore’s healthcare CPAs and advisors help organizations build these controls into everyday operations, and our Revenue Cycle Enhancement services examine the billing and collection processes where many of these risks begin.
Healthcare Compliance Now Means Reading Your Data First
CMS’s $3.4 billion crackdown and DOJ’s record takedown point to the same reality: Medicare and Medicaid fraud enforcement now moves at the speed of data. Honest organizations aren’t the target, but they live in the same dataset, and unexplained outliers will draw questions. Ready to see what your claims, vendors and referral patterns say before anyone else does? Talk with a James Moore healthcare advisor about strengthening the billing, documentation and vendor practices that help keep your organization from being flagged in the first place.
All content provided in this article is for informational purposes only. Matters discussed in this article are subject to change. For up-to-date information on this subject please contact a James Moore professional. James Moore will not be held responsible for any claim, loss, damage or inconvenience caused as a result of any information within these pages or any information accessed through this site.
Other Posts You Might Like