Fraud, Waste and Abuse (FWA) & Medicare Compliance

Annual training required by CMS for first-tier, downstream and related entities contracted with Medicare Advantage or Part D. Covers the distinction between fraud, waste and abuse, the False Claims Act, the Anti-Kickback Statute, the Stark Law, exclusion screening, the seven elements of an effective compliance program, and whistleblower protections.

Improper payments in Medicare and Medicaid are measured in tens of billions of dollars a year. Most of that is not organised criminal fraud - it is billing that was wrong, documentation that did not support the claim, and services that were not medically necessary. That distinction is the reason this training exists.

CMS requires Fraud, Waste and Abuse training and general compliance training within 90 days of initial hire, and at least annually thereafter, for the workforce of Medicare Advantage and Part D sponsors and for their first-tier, downstream and related entities - the FDRs. If your organisation contracts with a Medicare Advantage plan or a Part D plan, directly or as a subcontractor, this requirement reaches you.

New FDR oversight requirements take effect in 2026, tightening how sponsors verify that their downstream partners are actually training and monitoring their people. Expect attestation requests to become more specific and more frequent.

The consequences are not abstract. Individuals face criminal prosecution, civil monetary penalties, and exclusion from all federal health care programs - which ends a healthcare career, because an excluded individual cannot be employed by any organisation that bills Medicare or Medicaid, in any capacity, including administrative roles.

This course covers what the three terms actually mean, the four statutes that govern them, how exclusion screening works, what an effective compliance program contains, and your protections when you report a concern.

The three words are routinely used as one phrase, but they describe different conduct with different legal thresholds. The difference is intent.

Fraud is knowingly and willfully executing, or attempting to execute, a scheme to defraud a health care benefit program, or to obtain money or property from one by false pretences. Fraud requires knowledge and intent. Billing for a service that was never performed is fraud. It is a crime.

Waste is the overutilisation of services, or practices that directly or indirectly result in unnecessary cost. Waste is generally not criminally intentional - it is the misuse of resources. Ordering a duplicate test because nobody checked the record is waste.

Abuse occupies the middle ground: practices inconsistent with sound fiscal, business or medical practice that result in unnecessary cost, or in reimbursement for services that are not medically necessary or fail to meet professional standards. Abuse does not require intent to deceive but still results in improper payment.

Why the distinction matters to you: the reporting obligation is the same for all three. You are not asked to determine whether someone intended to defraud the program - that is for investigators and, ultimately, a court. You are asked to report what you observed. Deciding that something was "probably just a mistake" and staying silent is how patterns go undetected for years.

Medicare Advantage and Part D sponsors delegate a great deal of their work. CMS holds the sponsor accountable for that delegated work, which is why the training obligation flows downhill through contracts.

  • A first-tier entity has a direct written arrangement with the sponsor to provide administrative or health care services to enrollees - an IPA, a provider group, a pharmacy benefit manager, a call centre.
  • A downstream entity is any party that contracts below the first tier, at any level down to the individual provider - a subcontracted billing service, a credentialing vendor, a transportation provider.
  • A related entity has a common ownership or control relationship with the sponsor and performs some function for it.

The practical consequence is that a small billing company two contracts removed from a health plan carries the same training obligation as the plan itself. Many organisations discover this only when an attestation request arrives - a formal demand that they certify their workforce has completed compliance and FWA training within the required timeframe, and that they can produce records proving it.

Sponsors are permitted to accept the CMS standardised training modules as satisfying the requirement, and many FDRs use them. What sponsors cannot accept is an FDR that trained nobody and kept no records.

Keep your certificate. The attestation is only as good as the documentation behind it, and the entity that contracted you may ask to see completion records on short notice.

The False Claims Act (31 U.S.C. 3729-3733) is the government's principal civil tool against health care fraud. It prohibits knowingly presenting, or causing to be presented, a false or fraudulent claim for payment or approval to the federal government.

The word that catches people is "knowingly". Under the Act it does not mean only actual knowledge. It also covers acting in deliberate ignorance of the truth or falsity of the information, and acting in reckless disregard of it. No specific intent to defraud is required. A billing manager who never checks whether the codes submitted match the documentation is not protected by not having looked.

Civil penalties are substantial - a per-claim penalty adjusted annually for inflation, plus treble damages, meaning three times the government's loss. Because each individual claim can be a separate violation, a routine billing error repeated across thousands of claims becomes an enormous exposure very quickly.

The Act contains a qui tam provision allowing a private individual - a "relator", typically an employee - to file suit on behalf of the government. If the case recovers funds, the relator may receive a share. A large proportion of health care fraud recoveries begin with an insider.

The Act also makes it unlawful to knowingly retain an overpayment. Discovering that you were paid for something you should not have been, and simply keeping it, creates liability independent of how the overpayment happened.

The Anti-Kickback Statute (42 U.S.C. 1320a-7b(b)) makes it a criminal offence to knowingly and willfully offer, pay, solicit or receive any remuneration to induce or reward referrals of items or services reimbursable by a federal health care program.

Two features make it far broader than people expect.

"Remuneration" means anything of value. Not just cash. Free rent below fair market value, excessive consulting fees, waived copayments, expensive meals, sponsored travel, free staff, discounted equipment, and above-market employment arrangements have all been treated as remuneration.

The "one purpose" test. Courts have held that an arrangement violates the statute if one purpose of the payment is to induce referrals - even if there are other, entirely legitimate purposes. A consulting agreement that is genuine but priced to reward referral volume is still exposed.

Penalties include criminal fines, imprisonment, civil monetary penalties, and mandatory exclusion from federal health care programs on conviction. A claim resulting from a kickback is also a false claim under the False Claims Act, so violations typically compound.

The statute has statutory exceptions and regulatory safe harbors - defined arrangements that, if every element is met, are protected. Safe harbors are narrow and technical, and substantially complying is not complying. If your organisation has an arrangement with a referral source, it should be documented, priced at fair market value, commercially reasonable without regard to referral volume, and reviewed by counsel.

The Stark Law (42 U.S.C. 1395nn), formally the physician self-referral law, prohibits a physician from referring Medicare patients for certain designated health services to an entity with which the physician - or an immediate family member - has a financial relationship, unless an exception applies.

The critical difference from the Anti-Kickback Statute is that Stark is a strict liability statute. Intent is irrelevant. An arrangement that fails to satisfy an exception violates the law even if everyone involved acted in complete good faith and had no idea a problem existed. This is why documentation matters so much: a lease that was never signed, or that expired and continued informally, can create a violation where the underlying arrangement was entirely reasonable.

Designated health services include clinical laboratory services, physical and occupational therapy, radiology and certain imaging, radiation therapy, durable medical equipment, parenteral and enteral nutrients, prosthetics and orthotics, home health services, outpatient prescription drugs, and inpatient and outpatient hospital services.

Financial relationship covers both ownership or investment interests and compensation arrangements - including salary, rent, equipment leases, medical directorships and consulting fees.

Consequences include denial of payment, refund obligations, civil monetary penalties, and potential False Claims Act exposure. Because Stark has no intent requirement, the practical control is administrative discipline: written agreements, signed, current, at fair market value, and reviewed before they lapse.

The Office of Inspector General has authority to exclude individuals and entities from participation in all federal health care programs. Exclusion is the single most consequential sanction in this area for an individual, because its effect is total.

No federal health care program payment may be made for any item or service furnished, ordered or prescribed by an excluded individual. That prohibition extends to administrative and management services, and it applies regardless of who employs the person or how they are paid. An excluded receptionist at a practice that bills Medicare creates exposure for that practice.

Exclusions are mandatory for conviction of program-related crimes, patient abuse or neglect, felony health care fraud, and certain controlled substance felonies. They are permissive for a longer list including licence revocation, providing unnecessary or substandard services, and defaulting on health education loans.

Screening is done against two lists:

  • The OIG List of Excluded Individuals and Entities (LEIE), searchable free at oig.hhs.gov.
  • SAM.gov, the System for Award Management, which covers government-wide debarment.

OIG guidance is that organisations screen before hire or contracting, and monthly thereafter, because the lists are updated monthly and an existing employee can become excluded at any time. Screening must cover employees, contractors, vendors, volunteers and governing body members.

Compliance training often describes fraud in the abstract. In practice it appears as ordinary-looking administrative decisions. These are the patterns most commonly identified in enforcement actions.

  • Upcoding - billing a higher-level service than the one documented and performed. A routine visit billed as a complex one.
  • Unbundling - separating a procedure into component parts billed individually, when a single comprehensive code applies, to increase reimbursement.
  • Billing for services not rendered - including services documented but never delivered, and appointments the patient did not attend.
  • Medically unnecessary services - tests, imaging or therapies ordered without clinical justification, often driven by a standing protocol rather than the individual patient.
  • Misrepresenting the provider - billing under a supervising physician's number for services actually performed by someone whose services are reimbursed at a lower rate, or not at all.
  • Falsifying or backdating documentation to support a claim after the fact.
  • Waiving copayments or deductibles routinely - which can constitute both remuneration to the patient and a misstatement of the actual charge.
  • Prescription schemes - forged prescriptions, doctor shopping, pharmacies billing for brand while dispensing generic, or billing for refills never collected.

The common thread is that each begins as a small decision that made local sense. The scale comes from repetition.

Fraud makes headlines, but waste and abuse account for far more improper payment, and they are where most employees will actually encounter a problem.

Waste is typically a systems failure rather than a decision. Duplicate tests ordered because results from another facility were never retrieved. Supplies ordered on a standing schedule that expire unused. Extended stays driven by discharge planning delays rather than clinical need. None of it involves anyone trying to take money improperly, and all of it costs the program.

Abuse is closer to the line. Consistently billing the highest-level code because "that is what we always use." Ordering a panel of tests when one would answer the clinical question. Providing services that exceed what the patient's condition supports. Charging materially more than usual and customary rates. In each case there may be no intent to deceive, but the payment is improper and the exposure is real.

The organisational controls that prevent this are unglamorous: documentation that supports the code, periodic internal audits comparing billing patterns to peers, medical necessity checks before the service, and taking denials seriously as data rather than obstacles.

Your role is more limited but still material. If you notice that a particular code is used for essentially every encounter, that documentation is routinely completed after billing, or that denials for medical necessity are consistently ignored and rebilled, those are reportable observations. They are exactly the patterns that internal audit exists to find.

CMS and the OIG describe an effective compliance program in terms of seven elements. They originate in the Federal Sentencing Guidelines, and an organisation's ability to demonstrate them materially affects how enforcement treats a violation.

  • 1. Written policies, procedures and standards of conduct that articulate the organisation's commitment to comply and describe expected behaviour.
  • 2. A designated compliance officer and compliance committee, with accountability to senior management and the governing body, and with genuine authority and resources.
  • 3. Effective training and education at all levels - including this course - delivered on hire and annually.
  • 4. Effective lines of communication between the compliance officer and the workforce, including a mechanism to raise concerns anonymously and without fear.
  • 5. Well-publicised disciplinary standards enforced consistently, including for senior staff. Selective enforcement is itself a compliance failure.
  • 6. Effective systems for routine monitoring, auditing and identification of compliance risks - proactive review, not waiting for a complaint.
  • 7. Procedures for prompt response to detected offences, including corrective action and, where required, reporting and repayment.

The seventh element carries an obligation people frequently miss: an identified overpayment must be reported and returned. Retaining a known overpayment is itself a violation of the False Claims Act, regardless of how innocently the overpayment arose.

Compliance programs work only if people use them. The most consistent finding in enforcement actions is that somebody inside knew, and either had no route to raise it or believed raising it would cost them their job.

How to report. Most organisations offer several routes: your supervisor, the compliance officer directly, or an anonymous hotline. If the concern involves your supervisor, go around them - that is what the alternative routes exist for. Outside the organisation, reports can be made to the OIG Hotline, to CMS, or to the Medicare Drug Integrity Contractor for Part C and D matters.

What to include. Be specific and factual: what you observed, when, where, who was involved, which claims or patients if you know them, and any documentation. You are not required to investigate, to prove intent, or to be certain a law was broken. Reporting a good-faith concern that turns out to be nothing is the system working correctly.

Retaliation is prohibited. Section 3730(h) of the False Claims Act protects employees, contractors and agents who are discharged, demoted, suspended, threatened, harassed or otherwise discriminated against because of lawful acts in furtherance of an FCA action or efforts to stop a violation. Remedies include reinstatement, double back pay with interest, and compensation for special damages including litigation costs and attorney's fees.

Organisations must also have a non-intimidation and non-retaliation policy as part of their compliance program. If you experience adverse treatment after reporting, that is separately reportable.

This final module covers what is actually expected of you, day to day.

Know your organisation's code of conduct and compliance policies, and know who your compliance officer is and how to reach them. If you cannot name that person, that is a gap worth closing today.

Bill and document accurately. The documentation must support the code. If you are asked to change documentation after the fact to justify a claim already submitted, stop and raise it - that request is itself a serious compliance concern.

Verify before you act on an instruction that seems wrong. "I was told to" is not a defence under the False Claims Act, which reaches deliberate ignorance and reckless disregard.

Report promptly. Delay converts a correctable error into a pattern, and a pattern into an enforcement action.

Complete training on schedule and keep your records. CMS requires this training within 90 days of hire and at least annually thereafter. Your organisation may be asked to attest to a Medicare Advantage or Part D sponsor that its workforce has completed it, and that attestation must be supportable with documentation. Your completion certificate is that documentation - keep a copy where you can produce it.

One honest limitation. This course covers the statutes, definitions and program elements that CMS requires be taught. It cannot cover your organisation's own code of conduct, its specific policies, or the name and contact details of its compliance officer. Your employer must supply those, and you are entitled to ask for them.