Auditing, Managing Denials Is Important to Good A/R Hygiene
Auditing

Fraud Indicators and Red Flags, Part 3

Part 3: When Unscrupulous Managers Turn Auditors Against Their Coworkers or Teams   

Written by Carl J Byron, CCS, CHA, CIFHA, CMDP, CPC, CRAS, ICDCTCM/PCS, OHCC and CPT/03 USAR FA (Ret)

  

We Recommend Reading Part 1:  When Audit Managers Knowingly Skew Audit Results and Part 2: When Criminal Behavior Infiltrates Your Audit Program. This final article in the Fraud Indicators & Red Flags series addresses potential outcomes when lead audit managers sabotage the audit process due to being insecure or due to the need to secure power in their position.

Introduction

In the first two articles over mid-level fraud indicators, we covered signs and solutions to the problem individuals. In this article we cover signs and methods to address auditors who have been “turned” into internal threats or “moles”; informing on their coworkers and/or teammates.

When unscrupulous managers or audit leads act alone or in a conspiracy to maintain their position, they will employ many short-term tactics. Because they have to constantly defend their activities, they will not think in terms of strategies except in some form of escape plan (covered in part 2). Managers or lead auditors who target subordinates to become informants stands alone, both in severity and damage to good employees and ultimately the organization: mid-level leaders targeting individual subordinates they have found to be malleable, weak, or easily intimidated/worn down. This is especially damaging to teams as cohesiveness and trust are critical to their work.

How Employees Are Turned

Retaliation

According to the U.S. Equal Employment Opportunity Commission (EEOC), “The most frequently alleged bases of discrimination were retaliation (39.2%), sex (35%), disability (34.3%), and race (16.8%). At the end of FY 2023, the EEOC had 227 merits cases on its active district court docket, of which 95 (41.8%) were class or systemic cases. Mar 27, 2024”. In the realm of equal opportunity, we tend to think of discrimination in its most well-known forms: employment discrimination because of your race, color, religion, sex (including pregnancy, transgender status, and sexual orientation), national origin, disability, age (age 40 or older), or genetic information. However, many cases have been litigated where an employee was retaliated against by a superior for voicing concerns, ethical complaints and maltreatment because of their job functions. To "discriminate" against someone means to treat that individual differently, or less favorably, for some reason.

While close timing between the allegation of retaliation and the manger's action can display retaliatory motive, there have been cases in which years have passed and other evidence established that the employee's prior activities set off the manager's action. Even minus close proximity timing, other relevant facts may include verbal or written statements; comparative evidence that a similarly situated employee was treated differently; falsity of the employer's ostensible reason for the adverse action or uncovered plausible deniability; or any other evidence from which an inference of retaliatory intent could be assessed. From the EEOC’s perspective, retaliation can take numerous forms: reprimand the employee or give a performance evaluation that is lower than it should be; engage in verbal or physical abuse; increase scrutiny; make the person's work more difficult; to name a few.

Managers find ways to retaliate against subordinates for bringing forward worries about fraud or questionable conduct. Rather than listening to the employee, who is normally an expert, many employers instead resort to various forms of blaming the messenger, and good employees are often fired, moved, or blackballed/driven from the healthcare arena for their willingness to speak up.

As in the parts 1 and 2, information is limited how mid-level administrators target individuals: but there are a number of recurring behaviors and types of bad actors who seek to isolate and “turn” auditors against their coworkers and teams.

Decentralization and Isolation

These arise from the same flaw(s) in any system but are used differently by the fraudster in a leadership capacity. The managers in question exploit the trust and lack of supervision of their activities: what controls may exist can be overridden (technology) or deflected (manipulating reports, meeting statements, etc.). Information asymmetry is used to manipulate technological data and remove negative information from reports, information the auditor will never see. If or when inquiries arise plausible deniability is used and the lack of oversight fully exploited.

There are two environments managers or audit leads use to isolate subordinates they wish to control: the office setting and the remote workforce.

In the office, if an auditor voices concerns or acts in a manner the manager sees as threatening or the manager has found to be easily influenced the manager may move the auditor away from coworkers or teammates or vice versa; move the team to other offices. The auditor now has no one they trust or can communicate with easily, directly and, critically, confidentially. Movements are harshly scrutinized and timeframes are strictly set to further control movement and communications. This isolation can be further abused by either the manager promising to put the team back together if the auditor “behaves”: or, the auditor is now so isolated maltreatment can be carried out at the manager’s will and the auditor turned to report what the manager wishes to hear when the audit team meets and works. Either way the team has been effectively infiltrated.

In the remote environment the manager already exploits information asymmetry but now, since the audit team cannot see each other at any point (in my experience Zoom and visual-virtual meetings do not fill the void of direct interaction), pressure can be put on individuals in turn and cracks either caused or taken advantage of. When conspiring managers work together and keep unrelenting pressure through implied or real threats (as viewed by the targeted auditor) and they force the auditors to only communicate with them individuals can feel lost and without options.

Bullying and Disrespectful Behavior:

Unfortunately, these behaviors have no direct legal protection: unscrupulous managers know this. They use both a combination of Game Theory and perverse incentives against individuals and together bullying and disrespectful behavior can wear an auditor down making them more malleable to turn against their team. Because of scarcity of information and similarities in definitions, bullying in this article is synonymous with disrespectful behavior, as they are virtually identical in practice.

An August 11, 2020 article in Forbes magazine titled The Differences Between Workplace Bullying And A “Hostile Work Environment” put the problem of protection against bullying as follows: “What then separates, on the one hand, a workplace that is miserable due to a boss who is a jerk to the entire staff and, on the other hand, a Title VII hostile work environment claim? The key is that the abusive conduct must be related to the employee’s race, sex, religion, etc. (otherwise known as a protected characteristic) in order for the mistreatment to be unlawful under Title VII and related laws. For example, if a manager has everyone walking on eggshells because they yell constantly and set unattainable goals/deadlines—but this abuse is directed to all employees—then this is not illegal under Title VII. If, however, the supervisor treated only female employees this way, then these women could pursue a hostile work environment claim if the inequity is based on their sex.”

For disrespectful behavior I direct the reader to a 2017 article published by The National Institute of Health: Disrespectful Behavior in Health Care-Its Impact, Why It Arises and Persists, And How to Address It—Part 2 by Matthew Grissinger: “Health care organizations have fed the problem of disrespectful behavior for years by ignoring it, thereby tacitly accepting such behaviors.  The health care culture has permitted a certain degree of disrespect while considering this a normal style of communication. Studies have shown that disrespectful behaviors are tolerated most often in unfavorable work environments, but it is unclear whether poor working conditions create an environment where the behaviors are tolerated or if the dis respectful behaviors create the unfavorable environment.

Organizations have largely failed to address disrespectful behavior for a variety of reasons. First, the behavior typically occurs daily but often goes unreported due to fear of retaliation and the stigma associated with “whistle blowing.” Disrespectful behaviors are difficult to measure, so without robust systems of environmental scanning to uncover the behavior, concerned leaders may be ignorant of the problem.  Leaders may also be unaware of the behavior if managers shield them from this information because they view it as a personal failure. If disrespectful behaviors are known, leaders may be reluctant to confront individuals if they are powerful or high-revenue producers, or they may not know how to handle the problem. It’s not a topic taught in training programs, so leaders may hesitate to take on a problem for which there is no obvious solution.”

The Workplace Bullying Institute (WBI), established in 1997 tackles the issues of prevention and protection against bullying. Since their institute began they have been “advocates for anti-workplace bullying legislation in the U.S. having introduced the Healthy Workplace Bill in California in 2003 and 31 other states and two territories since, WBI, in collaboration with David C. Yamada, Professor of Law, Suffolk University Law School, Boston, now brings forward an alternative model bill the Workplace Bullying Accountability Act (WBAA).”

The WBI has the most widely adopted definition of workplace bullying: “Workplace bullying is defined as an “abusive work environment” characterized by: repeated verbal abuse; conduct that is threatening, intimidating or humiliating; defamation of one’s reputation; work sabotage, undermining performance; and/or orchestrated ostracism.”

The WBI identifies multiple types of bullies:

  • The Constant Critic: “This one draws its targets behind closed doors. There they can threaten and intimidate without witnesses. Most shocking is that they target the most competent, veteran, go-to worker and claim that that target is incompetent. The stunning big lie freezes the target. If they are ever reported, they deny what they said and did. To HR, it becomes a she said/she said unsolvable problem. Their favorite tactic is to manufacture a false performance appraisal.”

We immediately see use of plausible deniability. If the manager is investigated they have a story ready-made, which can neither be proven nor disproven. No matter who gets involved the manager can always fall on “That’s not what I meant”; and so on. Because so much work is done remotely today this bully can plan and plot, and “test the waters” to find who the best targets are.

This bully will also take full advantage of information asymmetry. They make themselves, or them and a conspirator, the sole reporting avenues for all work, reports and performance evaluations. With decentralization and lack of robust controls documents will be manipulated, changed or deleted and the target sees no options. The bully may also have the ability to remove or corrupt auditor files. They cover two bases by verbally ordering the team to never report concerns or problems to each other or their supervisor: they strangle open communications. Their second layer of concealment is that the team will recognize the statement as an order and any attempt to circumvent or jump over them will result in accusations of insubordination. Since the manager controls upward information flow they can report what they choose, in what manner they choose. This creates and sustains an adversarial relationship between the manager(s) and the team and initiates the isolation stage of their scheme.

  • The Two-Headed Snake: “One moment your lunch buddy and a hugger. Right after, they stab you in the back. They are intent on controlling your reputation. To destroy it, they either start, or fail stop, rumors about you. This critter is very difficult to catch unless someone tells you what the snake has said about you.” This type includes the manager who either is friendly/polite, or says nothing: then months later you get a call from a superior informing you they were approached by the manager and a complaint lodged.

The two-headed snake also heavily exploits plausible deniability. This bully will do two things simultaneously: negatively/falsely report the auditor’s performance to their superior(s) and to the executives and omit reports and concerns voiced by the auditor completely: and be professional to the superiors they report to but harsh and untruthful to the auditor.

  • The Gatekeeper: “The Constant Critic and Two-Headed Snake do things to people. They commit acts of omission. Gatekeepers bully by withholding resources you need to succeed. Their dirty tricks are acts of omission. What do you need? Time to do the job? It’s denied by an impossible deadline. Information? You are blocked from using computers and search services. Furthermore, your colleagues have been ordered to not help you with anything. New job and you need training. No training for you. No budget. Though the department party is paid for. Need light duty coming back from surgery as the doctor ordered? No way. Management knows best and if you don’t return immediately to full duty, you will be fired.”

The auditor victimized by this type of bully actually may have immediate options to “return fire”. In parts 1 and 2 we covered fraud red flags and indicators of managers: and behaviors recognized by both the DoD IG and The State of New York Comptroller were withholding information. If the auditor feels there is no other starting point this can be immediately reported and investigated.

The WBI also has a position statement which encompasses, to a large extent, traits discussed in parts 1 and 2: “We believe a majority of bullies adopt the tactics of bluster and bravado as a cover, a mask, for some underlying deficiency. In other words, bullying is a compensatory set of behaviors meant to overcome something lacking — technical competence, empathy, or even fraud and theft.” This statement highlights another recognized red flag: Indications that key personnel are not competent in the performance of their assigned responsibilities.

If you as an auditor feel bullied, you are not alone. In an online survey conducted by the WBI some concerning numbers appeared:

  • falsely accused someone of “errors” not actually made (71%)
  • stared, glared, was nonverbally intimidating and was clearly showing hostility (68%)
  • discounted the person’s thoughts or feelings (“oh, that’s silly”) in meetings (64%)
  • used the “silent treatment” to “ice out” & separate from others (64%)
  • exhibited presumably uncontrollable mood swings in front of the group (61%)
  • made up own rules on the fly that even she/he did not follow (61%)
  • disregarded satisfactory or exemplary quality of completed work despite evidence (58%)
  • harshly and constantly criticized having a different ‘standard’ for the Target (57%)
  • started, or failed to stop, destructive rumors or gossip about the person (56%)
  • encouraged people to turn against the person being tormented (55%)

The last bullet point is exceptionally worrisome in the context of this article.

Being Selectively Unreachable:

When auditors are in the middle of their work, they often need rapid response from leadership to assist in problems, questions or the usual suspect, the “speed bump”. Especially in the remote environment managers will use these two ways: first they will be unreachable-period. And they will force the auditor to only approach them. Or they could call the auditor and demean them over the phone for their lack of knowledge knowing even if the behavior is reported likely no one will accept a phone call alone as evidence. But the manager will be faster than lightning to reprimand the same person. A chokehold has been put on communication but only to the individual. This causes tremendous stress and increases uncertainty because the auditor knows what awaits if he/she asks peers or an immediate supervisor for help and it gets discovered.

How to Spot the Informant

The auditor who bad actors have turned has several elements: was the auditor a good productive team member or was he/she already sarcastic, pessimistic or argumentive? On top of that, is the employee in an office setting or remote?

The Good Employee/The Unwilling Informant:

This is the majority of informants. In the office this may be visible early such as the example of the manager moving the team out or moving the auditor far away from the team. The remote environment is much more complicated for the team and much easier for the bad manager. The team does not see each other: as we have discussed communications have been forced to only the toxic manager so interactions between team members is tightly controlled: when an auditor has been targeted and pressure repeatedly put on the one auditor what communications take place do not allow the team to see potential effects. As discussed earlier even if the individual attempted to communicate directly with an immediate supervisor (but below the manager’s level) and the supervisor approached the manager, a plausibly deniable statement was ready.

The Not-so-Good or Easily Turned Employee:

There was already some real or perceived wrong by the individual and the manager’s insertion to further their “game” was not entirely unwelcome. In the office setting this might be dealt with by the meetings called by the bad actor(s): they want the team to feel their power and, not uncommonly, keep the team off balance and perhaps even maintain a certain amount of fear. The team will see the individual and either by statements made, favoritism shown by the bad actor toward the individual or other observed actions the team can as a collective element see a problem on the horizon. If the disgruntled auditor is separated from the team withholding information can go both ways and damage minimized. If the auditor remains with the team the team can collectively watch for signs such as excessive complaining and arguing, even over small points; complaining about being uninformed by the team; undermining team efforts to improve work, conditions or reporting functions; and disengagement from the team (good auditors can act this way as well: remember they do not want to be controlled and this may be an attempt to clue in the team).

With good and bad auditors, the remote environment complicates things-a LOT. Now the team does not know when the manager contacts the informant auditor, or about what. Meetings are remote and again the team cannot see each other (these managers do not use visual-virtual media for their meetings: it is another means to isolate individuals). The individual can even go so far as to start and maintain low level conflicts between her/himself and other members (as the bad managers do by initiating and maintaining disputes and adversarial relationships with the team).

An important behavior to look for is territorial behavior. Remember this individual was not unreceptive to the manager’s insertion into their work environment: they will do what they can to ensure no other team member discovers the alliance.

Other ways bad managers isolate good auditors have been discussed: but as they are more than likely indicators of fraud, they have more immediate avenues for elimination. They include Excessive control/micromanagement and forcing all control into the hands of 1-2 individuals; unclear expectations/vague “guidance” (withholding official or clear guidance they do not want known or applied).

Solutions

First and always at any sign of trouble even if only suspected document, document, document and wherever possible make bullet points tying complaints to a specific noncompliance, such as carrying on continuous disputes with the auditor and give official links to the guidances you used or attach them as Exhibits. Try to keep date-time groups as accurate as possible; and who said what when. Document what routes were attempted and what results were.

Most managers and lead auditors are ethical, hardworking and care deeply for their subordinates and the organization. The bad actors are the minority. When concerns arise about managers behaving fraudulently or antagonistically toward an auditor and their supervisor or the team another manager must be found who can address the situation and stay the course of reporting with an individual and/or the entire team. When the bad actors show themselves go to the good people and seek pathways to resolution. These people should be sought out by the team early and included in meetings if possible: or at the very least independently communicated with by a trusted teammate. This way communications are open, honest and in all likelihood big problems can be averted if the direct reporting mechanisms fail. A manager who is willing to isolate and turn an employee is not on the job for the right reasons: so, we can infer some form of fraud is taking place: financial, position protection or something else. It must be addressed quickly.

Even if a team member is believed/known to be an informant I still recommend sequestered team meetings. These are two-edged swords: the informant can report information the team shares which they rather the bad manager not be privy to: at the same time meetings can include “project assignments” or additional duties assigned to each member-the supervisor will likely be the lead for this. The supervisor can then contact each auditor individually with specifics added to their assignments. After a time, consistencies will appear because the manager(s) will micromanage everything and the informant will have shown her/his hand somewhere. In the office setting the team will need to look for more visible signs, as listed above.

The supervisor or first line leader can work directly with the informant. An unwilling participant in any fraudulent enterprise will likely want their position betrayed: they respect their team and want no part of whatever the manager is up to. Reporting safety nets and protections must be offered: confidentiality must be strictly adhered to: and the promise made of rapid action must at all costs be kept.

No solution has value unless there is a structure in place to proceed with it. Most big organizations have a hotline: whether via telephone or email the hotline must be reviewed regularly and every concern addressed. Unlike most systems if an auditor has been unwillingly turned against their team and the supervisor is assisting in the reporting process there should be an avenue for immediate supervisor/trusted individual input. Secondhand information may not be ideal but likely the auditor-informant (called a relator) is scared, stressed and afraid of retaliation, possibly including against their team. If first line leaders have enough tenure, they will likely know a peer in compliance or risk evaluation and rather than indirect communications, they can expedite the relator meeting directly with a party who has the authority to kickstart the resolution pathways. If possible, a direct internal line of reporting is advised. If the organization is big enough there may be an Ombudsman’s office to help pave the way.

Compliance and human resources cannot sit on their hands: but many departments either failed to believe the relator, initiate a serious investigation, or adhere to strictest confidentiality. Because these fraudsters know and game the system they will know as long as they refrain from certain behaviors and statements, civil rights type arguments will find little traction. The relators know this also: and if they are willing to come forward, they must have airtight guarantees of confidentiality-of the case they have reported and their identity and work environment.

Fraudster managers will “lock up” as many avenues of communication as they can internally and depending on their current tenure other sections, perhaps even compliance has been duped or kept so inaccurately informed they trust the manager(s) too much (again, information asymmetry and plausible deniability).

It is also recommended external avenues be established such as an attorney’s office, the contracting organization if the entity is a government contractor, or even an Arbitrator who can direct concerns efficiently and timely to the correct people. These are not recommended as first paths. However, if a relator has any doubt about their safety, then external measures should be established. Therefore, the team, again perhaps the Lead or supervisor should establish an external compliance “escape route”.

Now the deep dive: if any breach of process is suspected or prior attempts at resolution have failed. This is not recommended but may be necessary if the people reported to do not behave in a manner fitting the complaint. The relator has attempted internal controls and found them ineffective, even with as clear documentation and reporting as possible. This action comes with serious risk, there is no doubt: but resolution was honestly attempted and failed. Advise the addressees the relator is willing to take the case as high as necessary, even to the federal level.

My recommendation would be to word it as an advisory: “I have told you what I know, I expect proof of response within X# of days. If I hear nothing, or I receive any indications my confidentiality has been breached I reserve the right in accordance with (company, contractor) policy to report this to all authorities concerned with this matter. I am making a final attempt to resolve this problem locally and it is hoped at this point my concerns will be taken seriously. But if not, when reported to federal authorities the matter is out of our hands.” This statement will be taken seriously as intended: you have an argument and we need to address it, and you consider it very important. Or they could view it as a threat. Officially reporting the manager should be enough and the receiver(s) of the report should not need an advisory statement like this: you reserve this powerful addition to inform the receivers that you will see the matter through until a conclusion is reached and closed. So, it is up to the relator and any ally he/she may have to determine where in the process this goes-but have it ready. The relator has reported it at the lowest possible level: he or she must now commit to reaching as high as necessary to ensure all parties are dealt with and corrective changes made.

Conclusion

The vast majority of mid-level leaders are ethical and know their success relies on the true, realized accomplishment of the audit team below them. Attempting to turn a good or bad employee will never cross their minds because they hold themselves to a higher standard; and know deep inside that open communication delivered concurrently to all team members will achieve the highest rates of success.

Even where fraudulent managers exist these ethical managers will be as intolerant of their antics as the auditors. They will likely be an effective early avenue of reporting even if others who should be directly involved have failed.

Unfortunately, the damage mid-level fraudsters cause far exceeds the number working in the healthcare arena. Systems, processes and departments (i.e. Compliance) exist only to be disregarded and outmaneuvered: and individuals are expendable at any point so their illegal enterprise will survive. Elimination will only be achieved by teams and individuals willing to report them and defend their peers, and team cohesiveness strong enough to let each member know they are trusted and the team as a unit will support and if necessary, defend them.

About the Author

Carl J Byron, CCS, CHA, CIFHA, CMDP, CPC, CRAS, ICDCTCM/PCS, OHCC and CPT/03 USAR FA (Ret)

Carl is an experienced professional and contracted auditor with the military. His background includes HCC auditing for CMS, coding and auditing for a large global healthcare network, and serving as a compliance educator and speaker for AIHC. He currently volunteers as a subject matter expert for AIHC, a non-profit licensing and certification partner with CMS.

Copyright © 2025 American Institute of Healthcare Compliance All Rights Reserved

Read More
Auditing, Managing Denials Is Important to Good A/R Hygiene
Auditing

Fraud Indicators and Red Flags, Part 2

Part 2: When Criminal Behavior Infiltrates Your Audit Program 


Written by Carl J Byron, CCS, CHA, CIFHA, CMDP, CPC, CRAS, ICDCTCM/PCS, OHCC and CPT/03 USAR FA (Ret)   

We Recommend Reading Part 1 Fraud Indicators and Red Flags – When Audit Managers Knowingly Skew Audit Results as this article is Part 2, “the rest of the story.”

Subsequent to Part 1 - Fraud Indicators and Red Flags, this article stresses the need for early detection of that rare, but dangerous potential fraud committed by the Lead Auditor or Audit Manager.  Members of the audit team realize that detecting a non-conformance often means there is likely much that has gone undetected. If you see something, say something, right?  But what if it is your boss managing the audit?

Introduction

In this article, the term Audit Manager and Lead Auditor is used interchangeably, even though there may be variances between these two titles.  Audits are conducted as part of the organization’s compliance program for the purpose of detecting non-conformances in order to take corrective action to improve compliance to applicable rules and regulations. 

The assumption is made that most organizations have internal controls, checks and balances and accountability built into their compliance program.  When those controls fail, the audit process can be jeopardized, skewing audit results with a potential devastating impact on the risk management process.

Organizations, regardless of size, should require the following elements within an audit: Plan, Execute, Report, Corrective action (P-E-R-C).  Smaller healthcare organizations may only have one internal auditor, while mid-size and larger organizations have a team of auditors. Someone needs to manage or lead the audit, even if it is a team of only one auditor.  If your organization doesn’t engage with an independent third-party contractor to periodically inspect the management of the audit team, you should.  Typically, your Lead Auditor is the most skillful within our organization.  For an effective program, engaging an unbiased audit expert to review and “audit” the management of how audits are conducted is a sound risk management decision. 

Let’s review why auditing your audit program is so important.

Below the Surface: Detecting What You Don’t See

If your organization detects a problem, it is likely just the tip of the iceberg.  What you don’t or can’t see is likely to be a much bigger risk factor that what you do see. 

The assumption is made that most organizations have internal controls, checks and balances and accountability built into their compliance program.  Hopefully, this article describes several ways to detect areas of potential fraud within your audit processes.

It is not uncommon for C-suite Executives to delegate the responsibility of establishing and maintaining an effective internal compliance control system to mid-level management, such as the Lead Auditor, who must implement such controls at a reasonable cost. This could conflict with the Lead Auditor’s goals of improving coding, documentation, billing accuracy and other business systems.

It is the Lead Auditor’s primary responsibility to provide assurance that reviews are conducted to detect compliance non-conformance and to lead the audit team through the P-E-R-C proves.  For an audit program to be effective, audits must be conducted and reported in a manner free from material bias, conflict of interest and performed in an objective manner.  We must admit, auditing is not guaranteed to catch every instance of fraud, waste and/or abuse.  If a problem goes undetected, does this reflect poorly on the audit team?  It could, and it could result in tarnishing the team’s reputation.

But what happens when audit results are consistently exceptional?  Repeated scores of, let’s say 96%, 97%, 98% accuracy where the target performance goal is at least 95% accuracy?  Are these results “real” or should they be questioned?  Can Auditor Managers and Lead Auditors sway audit results to improve their own performance? Is it possible that the compliance infrastructure is unintentionally designed to encourage willful misrepresentation resulting in false positive outcomes?

These are important questions to ask to ensure the appropriate checks and balances are in place.  In-other-words, who is auditing the Lead Auditor? 

When Information is Withheld or Altered

Most organizations have effective audit programs led by experienced certified healthcare auditors.  Audit Managers and Lead Auditors are skilled at giving leaders independent, objective assurance that something is true. And auditors are experts when it comes to internal controls expected during an audit; unless that information is withheld or altered. Lead auditors, through training and experience, should be able to detect fraud indicators and when these indicators involve claims, then financial fraud may also be considered triggering an internal investigation. But having this much power, can it open opportunity for willful misrepresentation?

Let’s look at the government auditing standards for a moment.  In the 2018 Revision of Government Auditing Standards, the US Government Accountability Office it states (page 175, Section 8.73): “Fraud involves obtaining something of value through willful misrepresentation. Whether an act is, in fact, fraud is determined through the judicial or other adjudicative system and is beyond auditors’ professional responsibility.” 

Section 8.74 states: “Auditors may obtain information through discussion with officials of the audited entity or through other means to determine the susceptibility of a program to fraud, the extent to which the audited entity has implemented leading practices to manage fraud risks, the status of internal controls the audited entity has established to prevent and detect fraud, or the risk that officials of the audited entity could override internal control. An attitude of professional skepticism in assessing the risk of fraud assists auditors in assessing which factors or risks could significantly affect the audit objectives.”

Is Manipulating the Audit Environment a Sign of Malicious Activity?

Manipulating any part of the audit process requires investigation. This can involve acts of self-preservation on the Lead Auditor’s part, perhaps to the extent they want to drive out the more experienced auditors on the team who can uncover and report true findings and irregularities.

It is likely that experienced auditors on the team they manage may observe and question “why” something has navigated away from protocol. A red flag is when the Audit Manager’s motivations are questioned, the question is deflected or goes unanswered.

In my experience, opportunities exploited and behavior often found in those who are committing fraud, waste or abuse are those listed below, in addition to the typical collusion and conspiracy which are better known:

Weak Internal Controls – The manager is not monitored

The manager knows if concerns are voiced, the controls are so weak that little will come of complaint(s)-the manager also already has a script in place based on plausible deniability. Hyper-compartmentalization is exploited: departments are territorial and do not share information, i.e. Compliance does not oversee or meet with the auditing department. This causes a black hole between critical control components. There is no guarantee of confidentiality or protection. This too is exploited.

Moral hazard

A moral hazard occurs when one party in a transaction has the opportunity to assume additional risks that negatively affect the other party. The decision is based not on what is considered right but on what provides the highest level of benefit, hence the reference to morality.  In my experience, one of the more common is the moral hazard of rationalization.

Rationalizations are the excuses people give themselves for failing to live up to their own ethical standards. "Moral hazard of rationalization" refers to the psychological phenomenon where individuals use reasoning and justifications to convince themselves that their unethical behavior is acceptable, essentially allowing them to engage in immoral actions while maintaining a positive self-image, thus creating a "moral hazard" by reducing the perceived negative consequences of their actions; it's essentially using logic to excuse morally questionable behavior.1

Thorough knowledge of the systems and/or programs/Information Asymmetry

This is a serious element because the fraudster will have superior knowledge and/or access to electronic programs and processes.  When the Lead Auditor or Audit Manager has unlimited power through technology to manipulate data, routine monitoring is recommended of how this power is employed.  This is all part of strengthening internal controls through an objective expert.

The Payoff Matrix

According to an article in the National Library of Medicine published September 2023, in the context of healthcare fraud: "The Payoff Matrix refers to a conceptual framework that analyzes the potential outcomes (rewards and penalties) for different actors involved in fraudulent activities within the healthcare system, considering the choices they make between committing fraud or acting honestly, essentially illustrating the potential gains or losses depending on their decision and the actions of other parties involved, like patients, providers, and insurers; it helps visualize the incentives and disincentives that could influence their behavior towards fraudulent practices.”2

This is difficult for the vast number of honest managers to understand because they care deeply for their processes, employers, and, most importantly, people. To the fraudster it is a game; there are winners, there are losers; there are moves and counter-moves. They see the auditors as expendable players rather than victims: and they see superiors and leaders as opposing players who will be beaten and outmaneuvered. In the context of this article, they secure their positions and remain champions of the game, to continue with little thought to their own possible loss.

Detect the Tip of the Iceberg?

Actions to Mitigate Risk

The compliance department must be active, in place and independent in authority and action. If the reader will indulge a few analogies, I will show how critical this section of any organization is. About the iceberg analogy used in this article – the Titanic, the mighty, “unsinkable” ship, cutting edge in every way in its time.  We know on April 14, 1912 the Titanic hit an iceberg and sank igniting one of the most remembered tragedies in history.

Experts disagree on why the ship struck the iceberg but there are recurring theories: poor watch crew alertness and/or training; no binoculars; and they just didn’t see it in time. Things they do agree on: the ship was sailing too fast in known iceberg waters and there were not enough lifeboats.

Your compliance department is like the watch crew - They must look for hazards (watch): search for hazards in the future (binoculars): and have the authority to order the captain to alter course no matter how inconvenient. A compliance department that has become complacent or does not monitor internal controls is ignoring speed: things in healthcare move quickly. Having an ineffective compliance department is like having these lookouts not just make the ship hit the iceberg; they back the ship up and make it hit the iceberg again. Compliance must also be the lifeboats. They need to listen to and address every concern raised and treat all parties equally-no one stands alone because of title or position and the corollary; no one is above scrutiny for the same reasons. And compliance must be trusted to maintain strictest confidentiality. Every individual who reports concerns must feel they will be protected and safe.

The rest of the iceberg

In this image, note the long flat tabletop just below the surface. Managers who commit fraud, especially for their benefit at the cost of everyone else’s, will form some sort of escape route.

They are willing to “take some heat” as long as their fraudulent enterprise survives. The compliance department has to destroy this STAT. If the managers are spoken to but nothing substantial really is done, then they have taken the ship, backed it up, repaired it (so they think) and sent the ship right back into the iceberg.

Invest in Infrastructure & Developing a Culture of Compliance

Your workforce must feel “safe” to report concerns and observations of potential fraud, waste and/or abuse.  This only happens when a top-down culture of compliance has been instilled within the organization and demonstrated by the items listed below.

Responding to complaints must be rapid and effective - Compliance must be several critical things, just like the military: it must be forward yet visible (Air Force). We know they are active and they are watching beyond their office desks. We see them. They also must be agile: able to respond to indications or complaints quickly.  Employees at every level must know these people are there, always gathering information even when unseen and are there to defend them if necessary.

Compliance must also be the Army and Marines - Employees (relators) must know how to report concerns to the compliance department in a safe manner and undetected by the Lead Auditor when the Lead Auditor is of concern. Confidentiality must be the operative philosophy. Like all the major services, they must be able to act independently with the backing of the highest levels of authority. Above all, compliance must dedicate itself to an overarching creed: never let the relator feel scared, threatened, harassed or intimidated. Any form of retaliation will not be tolerated.

Establish a Confidential Network - The Audit Team needs to find an avenue to escalate complaints, confidentially, to those tasked with compliance and especially whistleblower protections. This should be between each auditor and the compliance officer or someone within the Compliance Committee. There really is power in numbers and just like plausible deniability, there will be force in consistency of fact. Because the auditors are external to the auditees, and in the remote environment external to the Audit Managers, information and concerns can be shared and options discussed without fear of harassment, reprisal or retaliation. Facts can be shared and supported by other auditors’ experiences.

This element differs from strengthening internal controls in that the point of contact for concerns need not absolutely be someone tasked with receiving them by policy.

Strengthen Internal Controls - There is no cookie-cutter template for succeeding in this. Whether through complacency, old school ways of thinking or the bureaucracy-wide need for self-preservation and avoidance of “bad news,” weak internal controls have devolved into weakness for a reason. Following right on the heels of getting these people to listen may be getting the auditors to trust them. Our attempts at reporting have failed: why should we trust you now? This is a legitimate question which must be answered before real progress can be made.

Documentation – Over time facts and details can become unclear.  Documenting observations, gathering “evidence” and making record in a timely manner can help determine if the person altering data has made a material falsification requiring a more formal internal (or external) investigation.

Conclusion

The vast majority of healthcare managers are ethical, hard-working people who care about their organization both downward and upward. They are as outraged by fraud or someone on their team manipulating information.  In my experience, the majority of published reporting of mid-level fraud regards financial motivation. If any healthcare organization takes firm and consistent steps to maintain strong internal controls, the type of fraud in this article will never see light and be mitigated before any significant damage can be realized.

Although we have covered quite a number of subjects, the solution will be driven by the establishment of a superstructure founded on ferreting out truth from plausible deniability and weak internal controls. Without these other efforts will yield little.

About the Author

Carl J Byron, CCS, CHA, CIFHA, CMDP, CPC, CRAS, ICDCTCM/PCS, OHCC and CPT/03 USAR FA (Ret)

Carl is an experienced professional and contracted auditor with the military. His background includes HCC auditing for CMS, coding and auditing for a large global healthcare network, and serving as a compliance educator and speaker for AIHC. He currently volunteers as a subject matter expert for AIHC, a non-profit licensing and certification partner with CMS. 

References

  1. McCombs School of Business – Ethics Unwrapped https://ethicsunwrapped.utexas.edu/glossary/rationalizations
  2. National Library of Medicine – Study on the Path of Governance in Health Insurance Fraud Considering Moral Hazard https://pmc.ncbi.nlm.nih.gov/articles/PMC10543491/#:~:text=Combating%20health%20insurance%20fraud%20is,toward%20a%20non%2Dfraudulent%20state

Copyright © 2025 American Institute of Healthcare Compliance All Rights Reserved

Read More
Auditing, Managing Denials Is Important to Good A/R Hygiene
Auditing

Fraud Indicators and Red Flags, Part 1

Part 1:  When Audit Managers Knowingly Skew Audit Results  


Written by Carl J Byron, CCS, CHA, CIFHA, CMDP, CPC, CRAS, ICDCTCM/PCS, OHCC and CPT/03 USAR FA (Ret)

Fraud cannot be eliminated. No system is completely fraud-proof, as any system can be bypassed or manipulated. However, it can be detected early by paying greater attention to common fraud indicators. This article follows a road less-traveled by discussing the potential of audit managers knowingly skewing audit results causing unintended consequences within what appears to be a well-functioning compliance program.

Introduction & Defining Terms

The Office of Inspector General (OIG) provides compliance guidance documents for healthcare provider use.  There are also self-reporting mechanisms in place to report overpayments on the OIG website (Self-Disclosure) and Self-Referral Disclosure for voluntary self-reporting of overpayments on the Centers for Medicare and Medicaid Services’ (CMS’) website.  Detecting these errors resulting in potential overpayments is typically accomplished through efficient auditing and monitoring programs coordinated under the direction of the organization’s Compliance Officer or Compliance Department.  But is the oversight of the audits manipulated to achieve particular performance goals? Could it result in the “cobra effect” (explained further below). Is anyone monitoring the integrity of the Audit Managers?

Tons of information can be found on the Internet, books, articles, etc. on fraud detection and prevention in healthcare.  Typical publications and investigative reports illustrate involvement of providers, executives and even lower-level employees. 

But there is nowhere near the focus on mid-level managers; those who are the go-betweens of the C-Suites and Internal Auditors and their immediate supervisors. Because the monetary variance with the executives/owners is so different, they are left out.

In my experience, it appears that the mid-level fraud aspect is recognized primarily by two government entities, one federal and one state, which will be referenced throughout this article. The list of terms and definitions used throughout are below for reference.

Cobra Effect- a situation where an attempted solution to a problem inadvertently makes the problem worse due to unintended consequences. 

Conspiracy- Britannica defines conspiracy as “in common law, an agreement between two or more persons to commit an unlawful act or to accomplish a lawful end by unlawful means.” The Law Dictionary defines Criminal Conspiracy as “A combination or confederacy between two or more persons formed for the purpose of committing, by their joint efforts, some unlawful or criminal act, or some act which is innocent in itself, but becomes unlawful when done by the concerted action of the conspirators, or for the purpose of using criminal or unlawful means to the commission of an act not in itself unlawful.”

Indicators and Red Flags- For the purpose of this article the two terms are used synonymously: Signs of deception or suspicious aspects of behavior or misrepresentations that can lead to illegal payments or claims. 

Perverse Incentive(s)- An incentive (reward or motivation) that unintentionally leads to negative or undesirable outcomes.

Plausible Deniability- Although this can be found in dictionaries there is no official, or even strictly legal definition. An explanation is far more effective. By far the best is the updated July 17th, 2022 article in The Law Dictionary2. It is not nearly as neat as one would expect; but the article displays how fraudsters who game the system apply this in their daily activities:

“Plausible deniability is defined by the dictionary. But it’s not technically a legal term or defined in any legal documents. Which makes it a much looser term than it sounds. On top of that, plausible doesn’t mean trustworthy, possible, or even likely. Plausible means you could conclude that something might or might not be possible. But usually theoretically, superficially, or suspiciously. It doesn’t necessarily have to be a “reasonable” conclusion, either. In its broadest sense, the term usually points to a lack of proof. After all, innocent until proven guilty is the backbone of our legal system. So, if there’s no proof, it’s plausible they could deny it.”  The definition continues to state “Essentially anything illegal or unethical that can be explained away under an innocent and probable guise – true or otherwise – falls under plausible deniability. Even if the plausibility of the denial is suspicious. However, in the ‘60s, the CIA took the term and expanded on what plausible deniability means to them. And the CIA’s version is the one that became popularized.  To the CIA, it’s the act of withholding information from senior officials to protect their higher-ups in the event the information becomes public. Whether the information was actually withheld or not matters little in court if there’s no proof to the contrary.”  The Law Dictionary Article goes further and indirectly shows us the dangers posed by managers who use it:

“While it might seem like a minor tweak, the CIA’s definition puts blame on subordinates. This blame swap alleviates pressure on more senior officials. Which you may or may not frown upon.  And I get that. Most people expect superiors to be held accountable for the actions of the subordinates. But if they have plausible deniability, the senior officials can’t be held accountable. This is true even if the actions clearly only benefit the superior who “wasn’t” in the know.  It also applies if an implication was made that spurred on illegal or unethical actions. An example would be a sinister comment in a suspicious tone followed by an equally suspicious exaggerated wink. That is, providing the superior can write it off as a misunderstanding.  However, in cases where someone genuinely didn’t know something was happening, they can’t reasonably be held accountable for the other person’s actions. Regardless of management practices and chains of command, if someone really doesn’t want you to know something, they’re really just not going to tell you. Famously, Ollie North (Lt. Col. Oliver L. North from the Iran-Contra scandal) called this situation “absolute deniability.” Ollie’s argument was if you’re genuinely not aware of or did not do something, that’s not plausibility – it’s just not a thing.

This seemingly convenient loophole is meant to uphold the burden of proof. And – before you cry outrage – the burden of proof is for your benefit as well. So, it’s kind of important if you care about your rights. However, that’s not typically how we think of plausible deniability. And that’s certainly not how we’ve seen it pan out in the political or corporate arena. Real-world plausible deniability can (and does!) encompass things like thinly veiled threats, false advertisements, sexual harassment, stalking, discrimination against legally protected characteristics like race, age, gender, and sexual orientation, as well as a slew of other instances.”

Why Focus on Mid-Level Audit Managers?
The Data Speaks for Itself!

The Association of Certified Fraud Examiners (ACFE)1 conducts biannual surveys of its members and one of the questions is what effect the perpetrator’s position has on fraud. ACFE graciously has given me permission to use their surveys and data for this publication.

Since the surveys began in 1996, questions on the survey focused on fraud committed by position. Three positions were given by respondents:

  1. Executives/owners;
  2. Employees; and
  3. Managers.

A recurring trend emerged. The trend breaks down generally (but consistently):

  • Executives/owners account for the least number of cases but the most losses in money.
  • The employees by contrast account for the greatest number of cases but the least amount of monetary losses.

But the surprising result, given the relative scarcity of information, was on managers.

  • In every survey conducted, the ACFE found managers account for fewer cases than employees; but 250%-300% monetary losses.

The Data Speaks

Data gathered in 2018 was a sign of things to come. The ACFE survey found most perpetrators were either employees (41.2%/median loss of $50.000.00) or managers (39.5%). But the median loss due to managers was $150,000.00: 3 times that caused by employee fraud.

In the ACFE’s 2020 survey employees accounted for median loss of $60,000.00 and managers, $150,000.00 or 2.5 times that of lower-level employees.

Forward to 2022 and employees accounted for median loss of $50,000.00. Managers again took a far larger proportion of median losses, totaling $125,000.00 2.5 times that of employees. In the 2022 survey the ACFE also stated “Frauds committed by higher-level perpetrators also typically take longer to detect.” “One of the challenges of dealing with fraud committed by high-level perpetrators is that these individuals often have the ability to evade or override controls that would otherwise detect fraud. Additionally, fraudsters in positions of authority might bully or intimidate employees below them, which can deter those employees from reporting or investigating suspected wrongdoing. Both of these factors might contribute to the longer duration of frauds committed by high-level employees.”

The ACFE has completed its 2024 survey, with the following results:

  • Employee fraud caused a median $60,000.00 loss; whereas
  • Managers caused a massive $184,000.00 median loss.

In addition, the ACFE reported based on the surveys and monitoring over time, “Similarly, fraud cases perpetrated by individuals at higher levels of authority took longer to detect. The median duration of frauds perpetrated by employees was only 8 months…while frauds committed by mid-level managers had a median duration of 18 months….” (All figures and quotes used with permission of the Association of Certified Fraud Examiners).

NOTE: There are two reasons to retro back to 2018. One was to show the timespan and consistency of results. But the second is to show that the data was consistent even during the pandemic and afterwards. This opens an area gaining scrutiny: fraud committed in the remote workplace.

In the case of healthcare coding and documentation auditors, the primary directive is to ensure documentation is true and accurate: and that claims submitted reflect the work that was in fact accomplished and specific codes are correct for encounters. When claims become involved, there will always be a financial element.  However, performance and upward mobility within the organization becomes a component for dishonesty within mid-level audit management. Although most motivation to commit fraud is financial, coding and documentation audit manager performance is often based on coordinating information down for improved accuracy and upward to demonstrate the audit program is working.

A bigger issue is that red flags were unreported or intentionally misrepresented at a level beyond the auditors. This is where the mid-level leadership can be most dangerous as they form the “solid floor” to the corporate officers for upward transmission of information, and ostensibly a “Communications ceiling” for the auditors and their supervisors, ensuring information goes down to the respective components.

Guidance from the Department of Defense Inspector General (DoD IG)

In its current guidance Fraud Detection Resources for Auditors3, there is a subsection titled Management Related Fraud Indicators. This is interesting because of the mass availability of information singling out executives and employees but little recognizing mid-level involvement. The DoD IG opens the subsection with a key statement:

“Management sets the tone of an organization through its control environment. An organization’s control environment is the foundation of all other internal control components. An organization’s control environment includes integrity and ethical values, management philosophy, organizational structure, and self-governance. For a DoD contractor, active participation in a compliance program, integrity reporting, and the DoD Voluntary Disclosure Program are key parts of its control environment. The control environment provides both discipline and structure to the organization; therefore, auditors must consider management characteristics and influence over the control environment not only as fraud risk factors but also as fraud indicators along with the general and audit specific fraud indicators.”

Several of the sixteen indicators are reviewed below.

Fraud Indicators listed by the DoD IG4

Detect an inappropriate or unreasonable argumentative attitude?

  • Failure to display and communicate an appropriate attitude regarding the importance of internal control, including a lack of internal control policies and procedures; ethics program; codes of conduct; self-governance activities; and oversight of significant controls

This can be noticed by something as easily overlooked as never mentioning them. More importantly managers have oversight and execution authority of those internal controls. They have the ability to withhold and interpret the controls to their benefit at the cost or suppression of the auditors they are tasked to oversee. They may withhold compliance training, guidance, manuals or conferences on the controls and processes reporting or proliferate “training” of their own to such an extent the auditors become separated from compliance knowledge or reporting routes.

  • Displaying through words or actions that senior management is subject to less stringent rules, regulations, or internal controls than other employees.

At meetings managers will not mention who they answer to, or how. They stay silent on their responsibilities for compliance.

  • Hostile relationship between management and internal and/or external auditors. This would include domineering behavior towards the auditor, failure to provide information, and limiting access to employees of the organization.

In some ways this is a continuation of the indicator above: but is an escalation as now the manager is forcing an adversarial relationship, hoping to bring it to a confrontational level and the manager will feel justified in disciplining the auditor for insubordination or drive the auditor out of the organization completely.

  • Failure to establish procedures to ensure compliance with laws and regulations and prevention of illegal acts.

One of two things, or both, will occur: the managers will make themselves the only contacts to raise concerns or even ideas. The DoD IG, DHHS OIG and government contractors have complaint and whistleblower processes in place but if they are not enforced, investigated and confidentiality strictly adhered to, the auditor’s chances of a peaceful resolution are slim to none. Fraudulent managers know and exploit this and it is another tool in their scheme to silence a problematic voice in their environment.

  • Indications that key personnel are not competent in the performance of their assigned responsibilities.

This is one of the more common non-financially driven fraud motives; an audit manager will not have the training, experience or credentials of auditors they oversee. The manager cannot ask the right questions but feels their position is threatened by superior knowledge which can result in closing lines and compliance avenues of communication.

When the manager is incompetent to fill the role, every red flag is fair game. 

In addition, they justify their actions by telling themselves only they deserve the position: not even necessarily that they earned it. In one of the cases below, two managers are conspiring against the audit team.  The two managers involved did not even have certified auditing credentials, such as the Certified Healthcare Auditor (CHA) offered by AIHC.

In one case, the company had been in trouble with CMS several times. A current manager with no auditing credentials was emplaced to oversee random audits of Medicare claims: but audits quickly discovered that same manager was responsible for 84% of the continuing errors and retrospective audits showed the same manager was responsible for much of the trouble uncovered by CMS auditors previously.

  • The manager attempted to redirect the audits but the audit supervisor did have auditing training and defended the auditor and had already hammered out a solid audit plan and methodology, which the company’s compliance director and CMS approved; and she checked every item audited as a check-and-balance.
  • Soon the auditor and supervisor learned the company began getting serious inquiries from CMS about the managers’ lag time submitting the compliance audits and eventually they “had to downsize” right when another sanction appeared looming.

In total 9 people were downsized in the space of a week and in the middle of the “pack” or team were the auditor and supervisor. This experience exposes two glaring problems with manager fraud.

  1. The manager was untrained and did not know how the audit was built and demanded items with a certain ID (hers) be left out of all audits. Random means random-you cannot pick and choose which items you audit or report. It skews results and becomes a targeted audit: a type no recognized auditing organization allows when a statistically representative general sample is demanded.
  2. The manager did not understand what a universe or statistically significant sample was, or simple formulas for calculating them. The manager also did not understand the old axiom “numbers don’t lie”. The manager constantly attempted to reword, reinterpret or omit fact of the audits when the audits had to be reported to the executives. During a meeting the supervisor and auditor attempted to explain how CMS and the DHHS OIG used their statistical auditing system, called RAT-STATS. The outcome was no response and orders to continue with targeted audits.

Just as widespread, but carrying much higher risk: a manager can never be allowed to oversee and influence an audit where they have a direct stake in the audit outcome. No audit will be trusted. This goes back to the indicator about managers creating a hostile environment: they will have results altered by bullying, threatening or confounding the auditor or do it themselves and through use of plausible deniability draw suspicion on the auditor.

If there is conspiracy between the manager and the reporting executive or body, the damage goes from probable/possibly mitigated to unacceptably high risk. In this company there was conspiracy but CMS uncovered it later. I do not know what happened to the two collaborators but I do know the Compliance Officer, who saved the company multiple times from CMS prosecution, was let go not long after the auditor and the supervisor.

  • Undue interest and micromanagement. We live in the information age, where information travels almost as fast as thought (or at least as fast as typing skills). Managers who demand inclusion on all Emails, regardless of topic are suspect, especially when a seemingly unrelated Email is sent only to a coworker and a harsh Email from the manager is the result. The danger signs are clear. The Email never went to the manager-how did he or she intercept it? The Email was unrelated to any sensible matter the manager would be involved in-let’s say in this case I asked a teammate for a copy of a pdf document because in my thousands of emails and e-files I couldn’t find it. Then, why was I criticized?
  • A manager that claims disinterest or having no knowledge about a sensitive or high-profile issue in which you would expect management involvement. An auditor informs the manager the electronic system that pulls visits for audit has been only pulling specific dates or codes (remember, depending on the data, the system may be running its own targeted audit). The manager tells you offhandedly to “just do the audit”. Or you tell the manager coders are assigning codes specifically prohibited (let’s say they’re CMS-only codes) on commercial claims. The manager doesn’t even say thanks: just like “I’ll look into it if I have time”.
  • Failure to effectively follow-up on recommendations resulting from external reviews or questions about financial results. Failure to follow up on any serious concerns or recommendations from the audit team. This couples with the hostile work environment: rather than follow up professionally the managers criticize the auditors.

Thomas P. DiNapoli, State of New York Comptroller Red Flags for Fraud5

Several of these management level indicators were further detailed in a guidance recently released by the State of New York Comptroller in his fraud guidance Red Flags for Fraud, under Management Red Flags. Mr. DiNapoli states the problem slightly differently:

  • Managers engage in frequent disputes with auditors.

This can be read differently than the DoD IGs indicator in that here the manager instigates and maintains irritating, false or adversarial confrontations to bait the auditor into a situation which the manager can accuse the auditor of being insubordinate, or keep the auditor confused or confounded about what the manager “wants”. This can flow into appeals if the manager oversees challenges to the auditor’s findings. The manager will overturn the auditor’s error and use such vague or meaningless rationale that the auditor is forced to contact the manager and is sharply rebuked (again, the manager has avoided dealing with the auditor and supervisor). This tends to make the auditor continue contact, attempting to get a clear answer. Each time the manager increases the inflammatory rhetoric or vague verbiage and a cycle has begun. This is the entrance of a behavior/methodology addressed below - plausible deniability.

The Comptroller’s report also specifies a red flag related to indicators in the DoD IG guidance:

  • “Management decisions are dominated by an individual or small group”.

Managers who are willing to retaliate without cause yet staunchly refuse to discuss their perceived “problems” with the auditor and the supervisor and never forward concerns through the chain of command are dangerous: they keep vital information from the executives and compliance/fraud investigators above or laterally while oppressing their subordinates and keeping them uninformed. In scenarios I present later I cover operations where managers are in a conspiracy: if concerns or perceived negative information is communicated the managers meet with each other and no one else.

Mr. DiNapoli also saw the red flag he made independent of others:

  • “Manager reluctance or refusal to provide information to auditors and their supervisors”.

This links directly to multiple red flags in several ways. As mentioned appeals results will be intentionally confounding to the auditor which puts the entire power of the outcome in the hands of the manager. The problem escalates when the manager(s) are the first and highest reporting entity who receive audit reports. I have seen cases where information and/or data in an audit report was manipulated or deleted and conspiring managers made claims the auditor was remiss: which went into their records for future “disciplinary actions”. In one example even if the auditor keeps the reports in her or his e-files after a short amount of time the reports are deleted. The file is there in name but can neither be opened nor retrieved. This can tie in to the hostile work environment: the manager chastises an auditor for “errors”: but either never provides specific, official guidance or provides “guidance” of the manager’s making (a guidance was talked about at a meeting but never entered in an official manual).

Inconsistent, vague or implausible responses arising from inquiries or analytical procedures.

Mr. DiNapoli’s red flag above shows us officials do recognize the use of plausible deniability. In the manager’s sphere of influence this needs to be closely scrutinized by the executives and auditors: but especially compliance.

A red flag, actually two, were further noted by Mr. DiNapoli but are closely related:

  • There is a weak internal control environment; and
  • Decentralization without adequate monitoring.

This may be the most important red flag there is: every other indicator or red flag can be built from it. The managers scrutinize the auditors-but who is scrutinizing the managers? This gives fraudulent managers 2 key openings.

First: when not monitored consistently managers can manipulate almost anything: documents, conversation records, even information that goes up and/or down the leadership structure. Many boards and even civil courts will not allow mobile phone records because they can easily be manipulated.

Second, they can target any perceived threat or opposition without question or investigation. This is where auditors who attempted to resolve problems locally become whistleblowers. They attempt to use the reporting systems in place but because the managers failed to forward concerns to the reporting body above them the concerns never go up. In addition, with decentralization the higher authority often incorrectly trusts the manager because the “information” sent to them never covered complaints. Even worse, if the higher authority was part of the hiring process they have motivation to hide a potential hiring error.

Last in this group is a red flag usually associated with embezzlement, and often with employees: but it can happen in any setting, at any level where an individual wants absolute restricted control of information. This red flag is refusing vacations or promotions for fear of detection. Let’s expand an example from above:

  • The manager demands inclusion on all Emails and intercepts irrelevant Emails and rebukes the auditor.
  • Now let’s add that the manager is on vacation: and the Emails are still being intercepted whether relevant or not. The outcome is the same: criticism of the auditor for asking a question. Is the manager embezzling?

As auditors we cannot know that. So how is this a red flag? Because the manager still has a chokehold on information flow. Let’s extend this: the manager is on vacation and your team is informed to contact her or his peer, another manager in the same position. You do as instructed, and either the manager on vacation answers your Email: the other manager answers your Email but states he or she will meet with the other “to discuss”; and no one else. Or worse the manager on vacation calls you and the conversation becomes adversarial.

Another red flag: the use of plausible deniability

Some may think this is a term straight out of Hollywood but it is still very real whether the fraud is primarily to protect a position or financially motivated. No matter which red flag or indicator we cover, plausible deniability is guaranteed. A case I know of is a manager, contacting only an auditor who has raised several concerns, stating “your insubordination will not be tolerated. Any further complaints will result in your discipline and we will make sure you get written up”. The supervisor hears of it and speaks to the manager. The manager replies with “I never said that. I simply stated I needed more detail in the concerns your auditor was voicing”. It is believable (as far as it goes): but is a fabrication of what was said, actually saying nothing, and again is cutting off lines of communication. Another example is the Email intercepts I mentioned. A question gets asked. And the manager states “I was on PTO. I wasn’t even in the office”. The auditor has the response from the intercepted Email but the manager followed up with a phone call-the auditor’s word against a higher level authority. Or, the manager was careful but knew full well the adversarial position regularly taken against the auditor. The response Email will be vaguely worded or gray enough where “That’s not what I meant” could be viewed as a reasonable answer. A manager who uses plausible deniability regularly will have their own dictionary of denials at the ready.

Manager Red Flags in the Remote Environment

The pandemic forced remote work on many organizations; and many continue to use this scenario as they are taking second looks at potential savings. For the cost of X number of computers for remote workers, and evaluating in-person or in-office time now from a part-time view organizations are seeing potential cost savings in everything from previously assumed overhead such as electricity to space lease or rental and parking.

What would we term this relatively new motivation for fraud? I would say we call it decentralization. And because of this decentralization, the incentive to commit fraud increases; and involves every red flag and indicator we have discussed. In the office environment an auditor could find someone, even if a peer to relate problems to. Remote work by its nature separates people. Or, as the managers see it, isolates them. And some preliminary information I have seen this isolation is making employees at almost every level suffer. But how will a manager use this, and remote work in general to keep their position unquestioned.

This case encompasses both incompetent managers and remote fraud: but there are more angles to the remote aspect so I will put it here. Two managers had been hired recently: neither had certified auditing or compliance training, and the reason they were hired was never made clear. “New” processes were initiated but were not released to the audit team until significantly later with no feedback allowance; what CMS would term a “comment period”. Concerns were voiced but harshly rebuked; and auditors were singled out for disciplinary Emails only to them, sometimes also to the supervisor. Meetings with them, the supervisor and auditor were refused. When an auditor voiced concerns again the managers waited 6 months: then complained to an external manager and demand without cause the auditor be disciplined.

The two managers made it clear no auditee was to receive ≥ 10 errors: and if the auditor stood their ground and the audit went to appeal, or the auditee complained to them directly, the auditor would be disciplined and errors in the report overturned in favor of the auditee. This causes a serious compliance problem: the auditee does not dictate the rules, or any aspect, of an audit. This is a red flag not found easily but applies universally: the auditee cannot, under any circumstances be allowed to dictate the rules of the audit.

The overarching rule here is covered by every recognized auditing body I know of and simply put, an audit is governed by rules, regulations and laws-not the auditee. This is a point strongly made during my Certified Healthcare Auditor training.  If an auditee is allowed to determine parameters of an audit the audit becomes immediately suspect and the auditors vulnerable to fraud investigations against them. In this case conspiracy extends beyond the two cooperating managers: they have now allied with the auditees, who will likely not “turn on them” as a quid pro quo.

Concerns had been voiced for several months audit results were being skewed: the conspiring managers told the auditors they had no choice. But a record was kept of a random sampling of several months’ audits in a specialty area: and of 100 total visits, 90 were of a type with such limited codes it was nearly impossible to make mistakes. A third of those were postsurgical visits where not only the procedure codes were limited (to 1 only); the diagnosis codes were also severely limited to 1-2 codes only. And this is regardless of the documentation. For practical purposes it is almost impossible to arrive at 90 single-type visits with such mandatory restraints on code choice. Targeted audits have a place: after random audits have been completed, aberrations found and concentration needs to be more focused. But if an organization’s policy is random audits only, the manager has much to answer for.

This case fits in several categories and could be covered deeper in each: but now the managers’ game has an added dimension mentioned previously. When the managers knowingly skew the results of the audits, and the audits are government, meaning they will be compiled and presented to Congress, the managers have added collusion to their list of illegal behaviors.

Conclusion

By their nature auditors (and their oversight bodies) are adversarial. The auditors need to find errors to improve accuracy and reporting-and the auditees want to look the best because their throats are on the line when budget cuts come. Using plausible deniability the managers claim “We’re remote: we have no influence on the auditees, and we have records of reports filed. If anyone is acting maliciously it is the auditors.” Because of the remote workspace, decentralization and lack of strong internal controls the managers have avoided a problematic scenario.

About the Author

Carl J Byron, CCS, CHA, CIFHA, CMDP, CPC, CRAS, ICDCTCM/PCS, OHCC and CPT/03 USAR FA (Ret)

Carl is an experienced professional and contracted auditor with the military. His background includes HCC auditing for CMS, coding and auditing for a large global healthcare network, and serving as a compliance educator and speaker for AIHC. He currently volunteers as a subject matter expert for AIHC, a non-profit licensing and certification partner with CMS.

References

  1. Association of Certified Fraud Examiners: https://www.acfe.com/fraud-resources/report-to-the-nations-archive
  2. Plausible Deniability Definition, Examples, & Laws, Powered by Black’s Law Dictionary, Free 2nd ed., and The Law Dictionary: https://thelawdictionary.org/article/plausible-deniability/
  3. DoD IG Fraud Detection Resources for Auditors: https://www.dodig.mil/Resources/Fraud-Detection-Resources/Fraud-Scenarios/
  4. DoD IG Comprehensive List of Fraud Indicators: https://www.dodig.mil>Audit>Indicators Only
  5. Thomas P. DiNapoli, State of New York Office of the State Comptroller-Red Flags for Fraud: https://www.osc.ny.gov/files/local-government/publications/pdf/red_flags_fraud.pdf

Copyright © 2025 American Institute of Healthcare Compliance All Rights Reserved

Read More
Auditing, Managing Denials Is Important to Good A/R Hygiene
Auditing

Fundamentals of a Healthcare Internal Business System Audit

Written by Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, OHCC, ICDCT-CM/PCS 

Because healthcare organizations are heavily regulated and periodically audited or investigated, conducting internal audits is important to mitigate risk. Internal audits can be an integral part of your corporate compliance program and used as an effective management system, whether it is focused on quality, safety or any other business element. An internal audit, also known as a Management Audit, compares the implementation and effectiveness of the system against a standard as well as against its own internal criteria, as defined in policies, procedures and work instructions.

Introduction

Conducting business system audits is complex.  The information provided in this article is not comprehensive and not intended as consulting or legal advice.  The American Institute of Healthcare Compliance (AIHC) provides comprehensive training to certify healthcare auditors.  You may consider enrolling in the online Auditing for Compliance course. 

Undecided about becoming an auditor?  Watch these recorded webinars posted to the AIHC YouTube channel, then decide.

What is a Business System Audit?

An audit is a process of comparing actions and/or results against defined criteria.  Simply stated, an internal audit evaluates a health care organization’s management capability to determine answers to the following questions:

  • Does a system exist?
  • Is it implemented?
  • Is it compliant to industry standards?
  • Is it effective?

What is “defined criteria”?

Criteria is defined as the plural form of criterion, the standard by which something is judged or assessed.

  • “Defined Criteria” are standards identified in advance and approved for use in a specific audit, generally set by government rules, regulations or government agencies, such as CMS or pre-approved by the governing board of your organization.

Are You Performing a First, Second or Third-Party Audit?

A first-party audit is performed within an organization to measure its strengths and weaknesses against its own procedures or methods and/or against external standards adopted by (voluntary) or imposed on (mandatory) the organization.

  • A first-party audit is an internal audit conducted by auditors who are employed by the organization being audited but who have no vested interest in the audit results of the area being audited.

A second-party audit is performed by a legal or consulting firm or an individual retained to perform the audit for your organization for process improvement and risk management purposes.

A third-party audit is performed by an audit organization independent of the health care organization and is free of any conflict of interest. Independence of the audit organization is a key component of a third-party audit. Examples of these types of audits would be a Joint Commission, or CMS (Centers for Medicare and Medicaid Services) contractor audit. 

  • Third-party audits may result in certification, registration, recognition, an award, license approval, a citation, a fine, or a penalty issued by the third-party organization or an interested party.

Compliance is the Focus of All Audit Efforts

You are auditing for compliance. Compliance must be the focus of all your efforts. The auditor must first completely understand compliance standards for the purpose of auditing competently. Compliance standards must be written, staff trained, procedures implemented and followed, and monitoring performed to ensure the standards are being understood.

Fundamental Phases of an Internal Audit

Internal audits should not be limited to a business system or elements thereof, but should also incorporate Processes and Services where applicable. Whether there is one auditor or many, someone must lead the audit project.  So, even if you are audit “team” of one, you must lead the audit process. 

An auditor may specialize in different types of audits based on the audit purpose, such as to verify compliance, conformance, or performance. An auditor’s skills need to encompass the ability to provide advice and corrective actions when non-conformances are detected.

An internal business system audit has four fundamental phases – P E R C

  1. PLAN
  2. EXECUTE
  3. REPORT
  4. CORRECTIVE ACTION
PERC


The Planning Phase

Getting organized is crucial to a successful audit outcome.  Never just jump in and begin auditing.  The audit is significantly affected by poor planning and the opposite is just as true; great success can be realized when the audit is well planned.   Before starting the audit, it is important to determine if there are any potential conflicts of interest where your determinations could be considered biased.  Next, are you competent and considered a subject matter expert for this type of audit? 

Next, realize that without preliminary information, planning, and understanding the criteria to audit against, your results are not likely to be on point! You may have to start the audit over completely if, as the Lead Auditor, you don’t understand the audit objectives from the start.

Drafting an audit plan includes writing down (at minimum) the following elements:

  1. Purpose of the audit;
  2. Objective (what is to be accomplished);
  3. Time frame & deadlines (start and completion dates);
  4. What items will be inspected;
  5. How many items will be inspected;
  6. How many auditors you will need; and
  7. Expertise required of the auditors for this project.

The seven items listed above become the introduction in your Report of Findings. Document this information sufficiently for ease of copying into your final report.

The Executing Phase

The best results come from building understanding and trust. Executing the audit is important and cannot be accomplished without cooperation from all parties involved in the project. You have only one chance to “launch” the project and do it well. 

Develop a rapport with the auditee. Meeting to maintain communication is essential to develop trust throughout the audit process. Effective time management is important for several reasons:

  • As a Lead Auditor, you have project deadlines to meet and likely have more than one project to oversee at a time. You need to work SMARTER, not harder!
  • Remember, you are managing the expectations of your boss and the auditees. You have to collaborate and maintain transparency.
  • Expect conflict – especially with difficult auditees which can “eat” up your time. Schedule conflict resolution time into the project.
  • Your team must meet deadlines in order for you to complete the project. Therefore, it is important for your audit team to work effectively. They watch everything you do, so remember that you are their role model.
    • Coach your staff. Be fair and impartial. Always be professional and expect your staff to always be professional. Part of being professional is respecting others time.

Utilize your leadership skills to influence the behavior of others to solicit cooperation. This all leads to efficiency and improved time management. Create checklists to stay on track.

Execution Activities

  • Organize and document the Audit Standards and Criteria to be used to determine non-conformances
  • Schedule and conduct the Opening Meeting
  • Collect Data/Information
  • Verify the information and measure compliance or non-conformances
  • Record the non-conformities

Collecting Data/Information to Inspect

The purpose of the audit is to collect objective evidence regarding the effectiveness of a specific system, process, etc. In general, these audits should be a dynamic and practical tour through the business management system along a path prescribed by the auditor’s program and checklists which are aligned with the audit objective.

Collect relevant data! An auditor can gain much information by interviewing associates, observing activities or documenting evidence found in certain records. Interviews should not be limited to department heads, as everyone has a role to play in a business system.

Keep in mind that “hearsay” evidence is unacceptable to use as a basis for a non-conformance. You can, however, use the information to check if a discrepancy indeed exists. Without “hard” evidence, such as documented proof or an observation with your own eyes, you must give the auditee the benefit of the doubt.

Ask Questions – which is the best way to collect information to verify that your audit is heading in the right direction.  Every auditor develops his or her own style and technique of questioning which evolves through experience and is fine-tuned on the basis of past successes and failures. The latter are bound to occur at some point, particularly when the auditor is new to his/her task and liable to errors both in commission and omission. Past experiences like this can be turned to advantages only if the auditor is willing to learn from them. 

These are six words to remember which, when properly used, force a response:

  1. HOW?
  2. WHAT?
  3. WHY? WHY? WHY?
  4. WHEN?
  5. WHERE?
  6. WHO?

You may need to ask” why” as many times as necessary to get to the details needed for a thorough investigation or inspection of a process.

Verify your Observations

Auditors have to examine samples of documents, equipment, charts and so on to verify their observations. These samples constitute the framework for the audit with the sample size at the discretion of the auditor.  When selecting samples for examination, politely insist on selecting the sample rather than asking the auditee to do so.

  • The samples selected by the auditee are rarely random and more than likely will be the information that the auditee wishes you to see rather than what you might select.
  • Remember that this is your audit and if a piece of information is missing you have the right to ask for it. However, it is crucial that you maintain a polite demeanor and remain objective in your audit activities.

Monitoring Audits

Monitoring follows the baseline audit. A monitoring system is usually initiated because of findings from the baseline audit. Monitoring is performed to assure continued compliance of the practice or facility after the initial or baseline audit. The objective is to measure process improvement. There may be multiple risks identified in the baseline audit resulting in various monitoring audits to be scheduled. 

Monitoring should be conducted on a scheduled basis and should include such activities as:

  • Reviewing utilization patterns
  • Creating new comprehensive, focused audits to be performed
  • Evaluating computerized reports (month-end and special reports)
  • Assessing reimbursements (denials, EOBs)

Analysis and reporting after the audit are critical to set appropriate criteria for monitoring the process.

The Reporting Phase

The Lead Auditor must be prepared to statistically report audit findings and have the capability of understanding statistical results. Calculating error rates, accuracy ratios and breaking down findings into numeric values is an important component of the Report of Findings.

Analyze the data collected.  In evaluating the results of an audit, be aware of the possibility of data acquisition errors. Using erroneous data can be worse than using no data at all.

  • An error in data acquisition occurs whenever the data value obtained is not equal to the true or actual value that would have been obtained in a correct procedure.
  • Such errors can occur in a number of ways. For example, an auditor might make a recording error, such as the transposition of a scored value of 25 on an audit checklist, to that of a value of 52 on an excel spreadsheet.
  • Data should also be reviewed for unusually large or small values, called outliers, which are candidates for possible data errors.

Graphic illustrations such as charts, bar or pie graphs, etc., can be used to illustrate findings. Understanding how to use formulas is necessary to perform these functions. Accuracy and reliability of the reports will lend credibility to the entire audit endeavor and to the reputation of the Lead Auditor.  Always write the report with your audience in mind.  Choose charts, graphs, illustrations and data which can be understood by the reader.  But before drafting the report, there are a few things to do:

  • Verify the results of the non-conformances
    • Be sure results are reproducible by other auditors on the team.  Ensure the standards used are appropriate. Validate the error calculations and expand the sample size to ensure it is representative of the “universe”.
  • Verbally share verified results with your immediate supervisor
    • If you are an external auditor, performing an internal audit/review, verbally share results with the person retaining your services.
    • An external auditor performing an internal audit/review should evaluate whether the project should be part of attorney-client privilege before sharing written results of any kind with the practice or provider.
  • The audit reveals a potentially serious problem
    • If “severe” or “disturbing” non-conformance is unveiled during an audit, initiate questions to gather important information.
    • Does the non-conformance have a “trend” – is it the same error or type of error made over and over by the same provider or is it systemic?  You may need to conduct a trend analysis.
    • If you are unsure about the seriousness of the non-conformance, speak with your supervisor and suggest seeking consulting or legal advice prior to documenting a formal report.

When Documenting the Report of Findings

  • Never make assumptions. All statements should be objective and backed up by evidence or “proof”. Be concise and report what you actually know, not what you “think” may be happening;
  • Start the report with an overview so the reader understands who, what and why the report was generated;
  • Provide an “executive summary” – a higher-level, bottom-line report of your findings. It is a summary of the results of the audit. Provide charts, graphs and other illustrations – “a picture is worth a thousand words”. Keep it short and concise;
  • Provide the details of your findings which support what is in your executive summary;
  • Use appropriate formulas and be sure your calculations are accurate; and remember -
  • Do not exaggerate. Be honest when sharing your concerns. State only facts that can be supported by examples and supporting documentation in your audit findings and workpapers.

The Corrective Action Phase

Once the Report of Findings has been issued, someone needs to be responsible to follow through to ensure improvement takes place. This responsibility usually falls on the organization’s Compliance Officer. Corrective action is taken to address a system failure to ensure that it won't happen again, subsequent to a non-conformity raised during an audit.

To take corrective action, you must be clear about the who, what, when, where, and why.  This typically involves conducting Root Cause Analysis.

Corrective action includes refunding overpayments revealed during the audit.  This must be done according to payer guidelines and may involved self-disclosure to the Centers for Medicare and Medicaid Services (CMS) or the Office of Inspector General (OIG).  Federal law requires entities repay any overpayments received from Medicare or a State Medicaid program within 60 days after identification.

Corrective Action Request Follows the Report of Findings

A Corrective Action Request should be issued to the auditee(s) after management has reviewed the audit report. Why?

  • Because an audit uncovers areas where the system is not functioning in accordance to documented standards such as procedures and work instructions.
  • Because an audit can identify the illness, but does not provide a cure. It must be followed by effective corrective action.

Corrective action activities involve:

  1. Identify the non-conformity (generally stated in the Report of Findings);
  2. Conduct Root Cause Analysis (to identify the underlying cause(s));
  3. Issue a Corrective Action Request with timetables and assigned responsible associates (assign accountability to have systems corrected, conduct training, etc.);
  4. Evaluate corrective measures taken (benchmark against previous performance, typically measuring against the Baseline Audit or the most current audit findings);
  5. Maintain accurate records to verify the corrective action has been completed [PDCA – addressed below].
  6. “Close-out” completed corrective action requests.

Management must assign follow-up activities with a designated champion.

  • The objective of internal auditing is to determine if the business system is implemented and if it is effective.
  • The objective of corrective action is to improve the business system.

Conclusion

When internal auditing and corrective actions do not function properly, the business system decays. Auditors need to be aware of this and take nonconformances in these areas very seriously. These two elements tell the whole story about a company’s understanding of and commitment to the quality system. The internal audit is best suited to verify effectiveness.

The task of an internal auditor is two-fold:

  • Does the system comply with OIG Compliance or other Standards and Requirements (Joint Commission, HIPAA, etc.); and
  • Is the system complete, relevant and consistently applied?

If internal audits are performed with these perspectives in mind, they can assess the effectiveness of processes, offer a constructive view of the business system and performance, and be an extremely valuable organizational tool.

About AIHC and the Author

American Institute of Healthcare Compliance (AIHCR) is a non-profit healthcare training organization and a licensing/certification partner with CMS.  The author, Joanne Byron, shares her clinical, consulting, auditing and educational experience by serving as the Board Chair of the and overseeing the AIHC Volunteer Education Committee.

Copyright © 2024 American Institute of Healthcare Compliance All Rights Reserved

Read More
General Compliance

Fraudsters Prey on Factors Influencing Health Outcomes

This article addresses various forms of fraud and how criminals’ prey on compromised citizens.  Contributions to this article are made from the American Institute of Healthcare Compliance Volunteer Education Committee’s interview of a law enforcement official.   

There are many factors which can influence our health, and in turn, there are just as many schemes which are actually considered health care fraud.

Social determinants of health (SDoH) are the nonmedical factors that influence health outcomes.  They are the conditions in which people are born, grow, work, live, and age, and the wider set of forces and systems shaping the conditions of daily life. While healthcare providers focus on how to capture SDoH data on patients to improve health outcomes, a counter force may be working in the background which hurts struggling families as they fall victim of fraud schemes.

SNAP Fraud

Food assistance is generally referred to as SNAP or food stamps. States may have their own names.  For example, in California it is known by Cal Fresh.  SNAP stands for Supplemental Nutrition Assistance Program and is the nation’s most important anti-hunger program.  The USDA administers SNAP food assistance through state food stamp programs.  There are directives and policies at state, federal and county levels that encourage healthy eating and lifestyles.  This can help most people to live or become healthy and contribute to positive mental health outcomes.

This government program provides food to low-wage working families, low-income seniors, people with disabilities, and other individuals with low incomes based on a sliding scale.  In 2021, SNAP helped an average of more than 41 million low-income people in the United States afford a nutritionally adequate diet each month.

How this Assistance Works

The Government (taxpayer) loads a debit card and the welfare recipient withdraws the money.  It is intended to provide the basics of food, shelter and clothing.  Policymakers at every level offer incentive and issue public service announcements for shoppers to “shop smart.”

The incentives take many forms. The foods that can be incentivized are fruits, vegetables, dairy and whole grains.  This takes place at small to national retailers, farmers markets and online SNAP retailers.  “Double Up Food Bucks” allows the shopper to buy twice the number of fruits and vegetables with each SNAP dollar.  SNAP participants can even buy seeds and edible plants to grow their own food. This can be a rewarding and empowering experience.

Other incentives include an Amazon membership discount, city bike-share programs, museum and zoo access, discounted YMCA membership and discounted internet access with device options.  Retailers can participate with online purchasing and delivery.  There is a special program that allows elderly, homeless and disabled SNAP recipients to purchase food at SNAP authorized restaurants.  On their own, retailers can offer other discounts and coupons for future purchases.

The debit card system (EBT), that serves welfare receipts, does not have a chip.   All you need is the account and pin number.  Newer EBT account cards may have the CVV code but it’s not required to complete a transaction.  Both of these features can offer verification that the account owner is the person using the card.

EBT Fraud – “It’s a Thing” with Criminal Gangs

Organized Eastern European criminal gangs, largely of Romanian origin, are responsible for ballooning EBT losses.  For just the month of May, 2023, California is reporting 8 million dollars.  The groups are intricate, diversified and organized. Google “EBT account skimming, device, welfare.” It’s a thing.

Gangs Breach UIB Accounts Too

The same groups are or were breaching Unemployment Insurance Benefits (UIB) accounts.  The crooks change their methods and technology frequently.  Compared to what these gangs are doing right now, much of the information easily found on the internet is old.

Most of the hardware, components and software are inexpensive and easily available from Amazon and eBay.  Currently, there are two notable methods.

  • One, the thieves are removing and replacing the keypad on self-checkout areas and sometimes regular register lanes. This type of skimmer captures the account and pin number.  They Bluetooth the data off the device from the parking lot.
  • The second method, at outside bank ATM’s, the crooks insert a thin metal or carbon fiber device into the card slot which reads and records the account number.  They also place a small piece of trim containing a camera and SD card above the terminal to capture the PIN.
    • The skimmer captures the account number and the camera shows the customer entering the PIN.
    • The crook inserts a known card into the ATM slot to show a starting point so they can match up the accounts to the PIN’s. To use the data, they have to retrieve the skimmer and camera.
    • The crooks then take the info and write it onto the magnetic strip of any extra card laying around, old gift cards, hotel room cards, and mailed card offers, etc.  Then they visit an outside ATM with stacks of cards and drain the accounts.

No fresh fruit and vegetables for you, my friend

Food and shelter are growing concerns for even the middle class.  The poor are taking the biggest hit.  Only some of the stolen EBT funds are replaced making both the taxpayer and the welfare recipient victims.

How about the Welfare recipient?  At the county level, they are encouraged to change their PIN monthly which means calling into a phone tree or visiting the local welfare office. Recipients are encouraged to check their account regularly. Most recipients’ benefits are siphoned off by the crooks during the 1st three days of the month. Don’t worry, it's Federal (taxpayer) money.

To report the loss, recipients must fill out form EBT 2259 and face a bit of scrutiny by their case manager.  One would expect some recipients to take advantage of the situation and some do.  Such as, having a friend spend the money or spend it anonymously on the internet and then claim fraud.  Case managers have to make a decision.  If they can’t figure it out, they may defer to county special investigations units (SIU’s).

According to the USDA, replacement benefits cannot exceed the actual amount stolen or the household’s benefit allotment amount for the two months immediately preceding the theft, whichever is lesser.

The USDA goes on to stipulate this can only happen twice per year.

Oh, guess what? The crooks are known to replace skimmers at the same locations the 1st, 2nd and 3rd of the month, EVERY month!

Conclusion

Criminals seem to stay one step ahead, creating more poverty in a situation which is already in crisis.

Rumors abound at adding a chip to the cards in 2024.  While it’s hard to spin this in the news media, especially considering political ambitions, welfare recipients are at a loss at the dinner table.  Millions of those in need are experiencing the stress of making due or going without.

Learn more about SDoH, and how capture and report for reimbursement purposes. The American Institute of Healthcare Compliance (AIHC) is a non-profit health care training organization. Want to volunteer?  Join us – for volunteer opportunities and member discounts.

Copyright © 2023 American Institute of Healthcare Compliance All Rights Reserved


Read More
Auditing, Managing Denials Is Important to Good A/R Hygiene
Auditing

You Play a Vital Role in Protecting the Integrity of the U.S. Healthcare System

Written by: Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS




The U.S. health care system relies heavily on third-party payers to pay the majority of medical bills on behalf of patients. Health care insurance fraud is a pressing problem, causing substantial and increasing costs in medical insurance programs. To combat fraud and abuse, all levels within a medical practice, hospital or health care organization must know how to protect the organization from engaging in abusive practices and violations of civil or criminal laws.


If you are a health care provider, remember that payers trust you to provide medically necessary, cost-effective, quality care. You exert significant influence over what services your patients get. You control the documentation describing services they receive, and your documentation serves as the basis for claims you submit. Generally, the health care system pays claims based solely on your representations in the claims documents.


When the federal government covers items or services rendered to Medicare and Medicaid beneficiaries, the federal fraud and abuse laws apply. Many similar state fraud and abuse laws apply to your provision of care under state-financed programs and to private-pay patients. The most important federal fraud and abuse laws that apply to healthcare are the:

  1. False Claims Act (FCA);
  2. Anti-Kickback Statute (AKS);
  3. Physician Self-Referral Law (Stark Law);
  4. United States Criminal Code
  5. Exclusion Authorities; and
  6. Civil Monetary Penalties Law (CMPL).

Implementing a successful compliance program not only assists in protecting your organization but individuals within the organization. It is crucial for providers, coders and billers to understand these laws not only because following them is the right thing to do but also because violating them could result in criminal penalties, civil fines, exclusion from the federal health care programs or loss of your medical license from your state medical board.


Government programs, such as the Centers for Medicare & Medicaid Services (CMS), find the investment in their audit and monitoring programs are effective. CMS announced in the fall of 2021 that their aggressive corrective actions led to an estimated $20.72 billion reduction of Medicare Fee-for-Service (FFS) improper payments over seven years.


When you submit a claim for services provided to a Medicare beneficiary, you are filing a bill with the federal government and certifying you earned the payment requested and complied with the billing requirements. If you knew or should have known the submitted claim was false, then the attempt to collect payment is illegal.


When an organization fails to provide training and education to deter and detect fraud and/or abuse, it is likely to be detected by an outside investigative source via action such as:

  • Focused audit by the payer due to detection of suspect billing patterns when compared to your peers;
  • Routine audits conducted by the payer, such as Medicare’s Comprehensive Error Rate Testing (CERT); and
  • Internal whistleblower or qui tam action.

Internal auditing and monitoring programs are essential to keeping medical records and billing accurate. However, a routine internal billing and documentation review could turn into a more focused internal investigation. During that investigation, is it possible that an aberrant pattern of inappropriate billing is revealed? Do you know how to proceed if this happens?


First, remember that anyone can commit health care fraud. Fraud schemes range from solo ventures to widespread activities by an institution or group. Your organization should have a designated Compliance Officer. Audit professionals should have the authority to report potential fraud and abuse situations directly to the Compliance Officer for further investigation and resolution.


Problem areas brought to the attention of the Compliance Officer should also be included in corrective action training programs to avoid the continuation of the situation. One of the most important aspects of a compliance program is training and education at all levels of the organization.


Now, let’s talk more about qui tam action. There are five potential areas in which qui tam cases arise related to Medicare or Medicaid claims and the False Claims Act (“FCA”). Qui tam claims involving Medicaid/Medicare healthcare vary, depending on the level of care needed and provided. Categories often involve allegations of total neglect or no services, worthless services, inadequate and inferior services and products, and aggressive patient treatment. Other areas of fraud involve misrepresentation of credentials, upcoding of services, unbundling of services, and misrepresentation of patient data or populations.


Words of Advice


Maintain accurate and complete medical records and documentation of the services you provide.

  • Ensure your documentation supports the claims you submit for payment. Good documentation practices help to ensure your patients get appropriate care and allow other providers to rely on your records for patients’ medical histories.

Anytime a health care business offers you something for free or below fair market value, ask yourself, “Why?”

  • Remember, when a vendor or consultant provides coding and billing advice, the provider filing the claim is responsible for the accuracy of that claim. Be suspicious when you are told that a huge enhancement of revenue will be realized if you bill like this . . .

Get expert advice from a qualified source before investing or getting into a joint venture.

  • Some physicians who invest in health care business ventures with outside parties, such as imaging centers, laboratories, equipment vendors, or physical therapy clinics, may refer more patients for the services provided by those parties than physicians who do not invest. These business relationships may improperly influence or distort physician decision-making and result in the improper steering of patients to a therapy or service where a physician has a financial interest. Arrangements could be viewed as illegal.

Avoid illegal incentives to join a hospital’s community.

  • A hospital may pay you a fair market-value salary as an employee or pay you fair market value for specific services you render to the hospital as an independent contractor. However, the hospital may not offer you money, provide you free or below-market rent for your medical office, or engage in similar activities designed to influence your referral decisions.
  • Admit your patients to the hospital best suited to care for their medical conditions or to the hospital your patients select based on their preference or insurance coverage.

Don’t sell free product samples.

  • Many drug/biologic companies provide free product samples to physicians. It is legal to give these samples to your patients free of charge, but it is illegal to sell the samples.
  • The federal government has prosecuted physicians for billing Medicare for free samples.
  • If you choose to accept free samples, you need reliable systems in place to safely store the samples and ensure samples remain separate from your commercial stock.

Relationships with the pharmaceutical and medical device companies

  • As a practicing physician, you may have opportunities to work as a consultant or promotional speaker for the drug or device industry. For every financial relationship offered to you, evaluate the link between the services you can provide and the compensation you will get. Test the appropriateness of any proposed relationship by asking yourself the following questions and when in doubt, get legal advice: o Does the company really need your specific expertise or input? o Does the company’s monetary compensation to you represent a fair, appropriate, and commercially reasonable exchange for your services? o Is it possible the company is paying for your loyalty so you prescribe its drugs or use its devices?

o  Does the company really need your specific expertise or input?

o  Does the company’s monetary compensation to you represent a fair, appropriate, and commercially reasonable exchange for your services?

o  Is it possible the company is paying for your loyalty so you prescribe its drugs or use its devices?


Educate C-Suite and Compliance Officials in Your Company


An executive, top-down approach is required for a successful compliance program. The following seven components provide a solid basis for a compliance program:


1. Conduct internal monitoring and auditing

2. Implement compliance and practice standards

3. Designate a compliance officer or contact

4. Conduct appropriate training and education

5. Respond appropriately to detected offenses and develop corrective action

6. Develop open lines of communication with employees

7. Enforce disciplinary standards through well-publicized guidelines


Establishing and following a compliance program helps health care providers avoid fraudulent activities and submit accurate claims. However, implementing mechanisms to develop a culture of compliance requires educating high-level influencers within your organization. 


Suggest C-Suite executives take online training in healthcare Corporate Compliance.

Require your Compliance Officer, Chief Executive Officer and Chief Financial Officer to become certified not only in Compliance, but in Auditing for Compliance and Conducting Internal Investigations.


Joanne Byron is the Board Chair and Chief Executive Officer of the American Institute of Healthcare Compliance (AIHC) with more than 35 years of health care coding, documentation, billing and compliance experience as a consultant, health care executive and corporate trainer. Learn more about AIHC, a 501(c)(3) non-profit training organization, today.  

Read More
Auditing, Managing Denials Is Important to Good A/R Hygiene
Auditing

Compliance & Internal Investigations

Written by: Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS




Are you an internal auditor conducting “routine” reviews? Have you ever uncovered erroneous or potentially fraudulent evidence? Once your suspicions have been reported to the Compliance Officer, were you asked to partake in evidence gathering during the investigation? The content of this article is for educational purposes and not intended as consulting or legal advice.


For those of you more experienced auditors, additional training in how to handle evidence during an internal investigation not only advances your career but helps secure evidence that can be used if an actual crime has been committed. I also recommend reading When Healthcare White-Collar Crimes Turn Red, an AIHC blog article from 2021.


Do you need to convince executives that crime is a potential problem for your organization? The Department of Justice (DOJ) posts “News & Noteworthy” cases here. 


What Comes to Mind When You Hear the Word “Forensic”?

 

Most of us think about investigations as seen on television programs, such as “CSI” or “Bones.” Forensic science is a critical element of the criminal justice system – “Forensic scientists examine and analyze evidence from crime scenes and elsewhere to develop objective findings that can assist in the investigation and prosecution of perpetrators of crime or absolve an innocent person from suspicion.”


According to the Merriam-Webster dictionary, the word forensic is defined as the following:

  • Belonging to, used in, or suitable to courts of judicature or to public discussion and debate
  • Relating to or dealing with the application of scientific knowledge to legal problems

Your auditing and compliance skills become valuable to professional law enforcement, but you need to know what, when and how to handle a situation which could potentially turn into criminal charges against someone within your organization. First, let’s start with prevention.


Is It an Internal or External Investigation?


Internal Investigations are conducted by skilled employees (or a consultant under contract working for the organization) trained to perform specialized audits to gather evidence when there is suspected fraud, abuse or crime. These investigations are typically conducted to gather information sufficient for legal counsel to determine whether an external investigation is warranted by the appropriate authorities.  These employees are often referred to as Internal Forensic Auditors or Internal Investigators. For the purpose of this course, we will refer to this position as an Internal Forensic Auditor.


Internal Forensic Auditors report to a Board of Directors, Compliance Officer and/or Audit Committee of the health care organization and typically work under the direction of the organization’s legal counsel.


External Forensic Auditors are independent of the organization they are auditing. They are experts working as an investigator for an accounting or consulting firm, CMS, a police department, the FBI or another agency as described above.


The process of conducting a forensic investigation is, in many ways, similar to the process of conducting an audit, but with some additional considerations. The various stages are briefly described below. 


Step 1: Accepting the Investigation


Review information regarding the matter and consider whether you (and your team) have the necessary skills and experience to accept the work.

  • Forensic investigations are specialized in nature, and the work requires detailed knowledge of fraud investigation techniques and the legal framework.
  • Investigators must also have received training in interview and interrogation techniques and in how to maintain the safe custody of evidence gathered.
  • Investigators must be able to address potential conflicts of interest or bias and achieve objectivity.

Step 2: Planning the Investigation


The investigating team must carefully consider what they have been asked to achieve and plan their work accordingly. The objectives of the investigation will include:

  • Recognize if there is sufficient evidence to warrant a forensic investigation. If so, then anticipate planning required to achieve the following:

      o Identify the type of fraud that has been operating, how long it has been operating for,
    and how the fraud has been concealed;

           Determine deadlines and timeframes to complete the investigation which may
    be driven by regulatory factors;

      o Identify the fraudster(s) involved;

      o Quantify the financial loss suffered by the organization;

      o Gather evidence for potential use in court proceedings;

           Identify the type of report format required and record evidence appropriately; and

      o Provide advice to prevent the reoccurrence of the fraud. 

The investigators should also consider the best way to gather evidence. They may choose the use of computer assisted audit techniques or other various methods appropriate for the situation.


Step 3:  Gathering Evidence – Fact Finding


In order to gather detailed evidence, the investigator must understand the specific type of fraud that is suspected. The evidence should be sufficient to ultimately prove the identity of the fraudster(s), the mechanics of the fraud scheme, and the amount of damage or loss suffered by the organization.


It is important that the investigating team is skilled in collecting evidence that can be used in a court case and in keeping a clear and secure chain of custody until the evidence is presented in court. If any evidence is inconclusive, or there are gaps in the chain of custody, then the evidence may be challenged in court or even become inadmissible. Investigators must be alert to documents being falsified, damaged or destroyed by the suspect(s). 


“Chain of custody” is defined by Dictionary.com as “the order in which a piece of criminal evidence should be handled by persons investigating a case, specifically, the unbroken trail of accountability that ensures the physical security of samples, data and records in a criminal investigation.” To prove the chain of custody, and ultimately show that the evidence has remained intact, prosecutors generally need internal investigators who can testify:

  • That the evidence offered in court is the same evidence they collected or received.
  • To the time and date the evidence was received or transferred to another provider.
  • That there was no tampering with the item while it was in custody.

Evidence can be gathered using various techniques, including: 

  • Testing controls to gather evidence which identifies the weaknesses which allowed the fraud to be perpetrated;
  • Using analytical procedures to compare trends over time or to provide comparatives between different segments of the business;
  • Applying computer assisted audit techniques which may help to identify the timing and location of relevant details being altered in the computer system;
  • Discussions and interviews with employees;
  • Substantive techniques such as: reconciliations, cash counts and reviews of documentation.

Step 4: Analyzing Data


After evidence and facts have been gathered and recorded, it is time to analyze all the data. The goal of data analysis is to determine if there is a relationship between the independent and dependent variables and to look for patterns within the data. 


Recording and organizing data may take different forms depending on the kind of information being collected. The way you collect your data should relate to how you’re planning to analyze and use it. Regardless of what method you decide to use, recording should be done concurrently with data collection if possible, or soon afterwards, so that nothing gets lost and memory doesn’t fade. Some of the things to do with the information collected can include:

  • Gather together information from all sources and observations;
  • Make photocopies of all recording forms, records, audio or video recordings, and any other collected materials to guard against loss, accidental erasure, or other problems;
  • Enter narratives, numbers, and other information into a computer program where they can be arranged and/or worked on in various ways;
  • Perform any mathematical or similar operations needed to get quantitative information ready for analysis;
      o These could include entering numerical observations into a chart, table, or spreadsheet, or figuring the mean (average), median (midpoint), and/or mode (most frequently occurring) of a set of numbers.
  • Transcribe (making an exact, word-for-word text version of) the contents of audio or video
    recordings;
  • Code data (translating data), particularly qualitative data that isn’t expressed in numbers, into a form that allows it to be processed by a specific software program or subjected to statistical analysis; and
  • Organize data in ways that make it easier to work with. This will depend on your research design and your evaluation questions.
      o Consider grouping observations by the dependent variable (indicator of success) they
    relate to, by individuals or groups of participants, by time, by activity, etc.
      o You might also want to group observations in several different ways so that you can study interactions among different variables. 

There are two kinds of data you’re apt to be working with. However, not all evaluations will necessarily include both.

  • Quantitative data refers to the information that is collected as, or can be translated into, numbers which can then be displayed and analyzed mathematically.
  • Qualitative data can be collected as descriptions, anecdotes, opinions, quotes, interpretations, etc. They are generally not able to be reduced to numbers and/or are considered more valuable or informative if left as narratives.

As you might expect, quantitative and qualitative information need to be analyzed differently. The investigation is likely to lead to legal proceedings against one or several suspects. Therefore, members of the investigative team must be comfortable with appearing in court to explain how the investigation was conducted and how the evidence was gathered.


Step 5: Report Your Findings


Draft the report in an objective manner. Do not draw conclusions, just report the facts. The checklist below summarizes what a typical report should contain:

  • Provide a Summary of the Investigation or Case
  • Describe the Investigation Plan
  • Case Notes – Keep an Investigator Diary
  • Information Interview Summaries
  • Interview Reports
  • Analysis of Investigation
  • Conclusion
  • Recommendations and Additional Action(s) Required With This Case
  • Exhibit Listing - attachments and evidence related to the case

Conclusion


An Ounce of Prevention Is Worth a Pound of Cure – So Learn More About Health Care Crime


A little precaution before a crisis occurs is preferable to a lot of legal complications, “bad press” and huge potential losses afterward. Preventing fraud in your organization starts with not hiring criminals! That might sound ridiculous, but are we really doing everything we should during the hiring phase of employees and contractors?


Most organizations are using the LEIE on the OIG website to screen new hires and conduct monthly verifications. But is this enough?


Unverified employees can put your organization at risk with a dramatic impact on your company’s brand reputation, performance and finances. Screening employees at hire, and periodically during employment, is a must for creating a safe workplace.


Below is a “short list” of screening tactics to consider before extending an offer to a candidate for hire. Be sure to review your procedure with legal counsel or a human resources expert to avoid any potential legal consequences with the U.S. Equal Employment Opportunity Commission (EEOC) related to changing your current hiring practices.

  • Criminal background check
  • Office of Inspector General (OIG) Exclusions Database check
  • Education – verify graduation, degree
  • Professional Certifications (check all certifications with the certifying agency – do not accept certificates from the potential employee as proof)

The EEOC has a webpage dedicated to help employers that addresses “Background Checks – What Employers Need to Know.” The information on this page is a joint publication between the EEOC and the Federal Trade Commission or FTC.


When making personnel decisions, which include hiring, retention, promotion, and reassignment, the EEOC states that employers should consider the background of applicants and employees. For example, the EEOC states you may want to consider verifying:

Except for certain restrictions related to medical and genetic information (per HIPAA, addressed further on the EEOC website), it's not illegal for an employer to ask questions about an applicant's or employee's background or to require a background check.


AIHC offers training – a “how to” participate in or conduct an internal investigation. The course is offered online with the option to certify (with a professional proctor online). The program is entitled Internal Forensic Auditor. If this course seems too intense, you may want to begin with the Auditing for Compliance online program.

Read More
Auditing, Managing Denials Is Important to Good A/R Hygiene
Auditing

Part 3: Audit Documentation to Avoid Potential Appeal Consequences

Written by: AIHC Blogger


This article provides educational information related to mitigating the risk of an unwarranted payer investigation. Only appeal claims when you have evidence and supporting documentation to substantiate your right to payment. This is the final article in a 3-part series on denials and appeals management. Read Part 1 entitled “Managing Denials Is Important to Good A/R Hygiene” posted March 22, 2022, and Part 2 entitled “Understanding How Payers Deny Claims.”


Audit Coding, Billing and Documentation for Accuracy


Insurance carriers and government contractors have the authority to review any claims at any time. Due to the huge volume of claims payers receive to process, deny and pay, they have implemented various methods to track providers to detect potential waste, fraud and/or abuse.


Providers may take documentation “short cuts” or feel overwhelmed with implementation of a new EMR (electronic medical record) system and clone or make documentation errors. It is important to detect any problematic areas prior to filing an appeal. 


Lack of detailed supporting documentation submitted with an appeal can not only result in another denial, but also in “flagging” your practice as being high-risk on the spectrum of potential fraud and/or abuse. It can result in a situation where insurance opens an investigation or decides to initiate periodic audits on your claims and records. When you believe the payer is making the mistake, push back by exhausting all appeal rights allowed. If the payer, such as Medicare, performs an extrapolation, reducing each overpayment dollar through appeal can mean thousands less to pay back.


Utilize the information provided in the Part 2 article, such as ensuring the claim meets Medical Unlikely Edits, bundling, diagnosis and medical necessity guidelines. All modifiers should be appropriately appended and supported in the medical record. A great free modifier resource to share with you is the CMS Medicare Administrative Contractor (MAC) “WPS” learning center with on-demand training materials. Click here for the WPS modifier page (choose a region, the website will take you to the page).


Place of Service (POS) can be a “trigger” for an investigation. If the claim is coded POS 11 for the office, reimbursement can be higher than if the same service was performed at the hospital by the provider. Audit the POS to ensure this was coded correctly on the claim. A complete national POS code set and instructions are provided in CMS Internet-only Manual (IOM) Publication 100-04, Chapter 26, Section 10.5 at:  

https://www.cms.gov/regulations-and-guidance/guidance/manuals/downloads/clm104c26pdf.pdf


Is the date of service (DOS) correct? When the medical record date doesn’t match the date filed on the claim, you may have a difficult time arguing an appeal. Payers always require documentation for the date of service filed (and paid) on the claim. When the DOS is incorrect, accept the denial. If you have not passed the timely filing deadline, re-file the claim with the correct DOS.


Audit to ensure your organization has no excluded individuals employed


An example of a case settled in 2022 is Windham Eye Group, an ophthalmology practice paying $192,000 for employing an excluded practice administrator. Please make sure your organization routinely screens employees to ensure none are on the OIG exclusions list. Prior to appealing a Medicare, Medicaid, TriCare or other Federal Program claim, you should verify that your organization is compliant in this area (click here). 


Evidence of Medical Necessity

 

Medical necessity includes frequency, duration, previous conservative treatment (that failed) and other factors. However, it also includes documentation of a supporting diagnosis.


The diagnosis coding on the claim is one of the first items insurance will review to qualify the claim as being “medically necessary.” Once the diagnosis coding passes through the insurance company edits, additional edits will then be performed against medical necessity criteria. 


Diagnosis codes are an important compliance aspect of reporting medical necessity on the claim. They are also a large contributing factor for potential fraud and abuse when documentation does not support the diagnoses reported. Auditing the diagnoses on the claim to documentation is a critical review step to determine whether the claim should be appealed.

  • Diagnoses should be sequenced according to coding guidelines.
  • Each line-item on the claim should be linked to the appropriate procedure code.
  • Audit the code to ensure all characters are accurate.
  • Each condition reported on the claim must be documented in the patient’s chart.
  • Verify that the primary diagnosis is listed as “medically necessary” for the treatment provided.

Detect a Problem?


During the course of auditing or reviewing documents related to a denied claim, you may identify situations where further investigation is necessary. You may state it is simply a billing error. Errors made over and over in high volume or high dollar amounts will be interpreted as more than a simple billing mistake by payers. 

  • Make careful consideration before appealing denials found on an investigational probe. 

Obtaining legal advice before proceeding with an appeal may be necessary under certain circumstances. 


Carrier SIU Situations


Insurance carriers have departments called Special Investigation Units or “SIU” with trained professionals carefully reviewing allegations of suspected fraud and abuse. 


When a probe or investigation is initiated by a payer in writing or in-person, it is likely the investigators have already been speaking with your billing staff and patients to gather information to establish a case against you.


Can the investigators “get it wrong”?  They can, sometimes!


There are times when investigators believe the situation is intentional (fraud) when the problem actually is being caused by lack of internal controls, auditing and monitoring by the provider. This allows errors to continue for prolonged periods of time.  


When your office receives the results of the SIU (carriers) probe, the letter will provide guidance regarding ability to appeal. If you are given the option to appeal, have evidence of a strong argument to support that these claims should be paid. If you can’t meet the deadline to appeal, request an extension to buy more time to audit and properly prepare your appeal argument. 


If your organization has a Compliance Officer and/or Certified Healthcare Auditor, you may want to bring concerning situations to his/her attention. Never file an appeal when you believe documentation may be evidence of fraud or abuse. You may need assistance from someone more highly trained in this area to determine this. If in doubt, check it out.


When speaking with your provider, Compliance Officer, Auditor or an attorney, the “short” list of rules and regulations which apply to medical coding, documentation and billing are listed below. 

  • False Claims Act (FCA);
  • Anti-Kickback Statute (AKS);
  • Physician Self-Referral Law (Stark Law);
  • Social Security Act; and
  • United States Criminal Code.

The difference between “fraud” and “abuse” depends on specific facts, circumstances, intent, and knowledge. Examples of abuse can include such things as:

  • Billing for unnecessary medical services (lack of medical necessity);
  • Charging excessively for services or supplies;
  • Misusing codes on a claim, such as upcoding or unbundling codes;

According to the Medicare Integrity Program, activities which target various causes of improper payments are items such as those in the chart below.


The government's primary civil tool for addressing healthcare fraud is the False Claims Act (FCA).

  • Most FCA cases are resolved through settlement agreements in which the government alleges fraudulent conduct and the settling parties do not admit liability.
  • Based on the information it gathers in a FCA case, the Office of Inspector General (OIG) assesses the future trustworthiness of the settling parties (which can be individuals or entities) for purposes of deciding whether to exclude them from the Federal healthcare programs or take other action.

The OIG's efforts to curb fraud include:

  • Conducting criminal, civil, and administrative investigations of fraud and misconduct related to HHS programs, operations and beneficiaries;
  • Using state-of-the-art tools and technology in investigations and audits around the country;
  • Imposing program exclusions and civil monetary penalties on health care providers because of criminal conduct such as fraud or other wrongdoing;
  • Negotiating global settlements in cases arising under the civil False Claims Act, developing and monitoring corporate integrity agreements, and developing compliance program guidance.

Because OIG's assessment of the risk posed by a FCA defendant may be relevant to various stakeholders, including patients, family members, and healthcare industry professionals, the OIG makes information public about where a FCA defendant falls on the risk spectrum.


The five risk categories on the spectrum are defined below:


Highest Risk:  Exclusion

  • Parties that OIG determines present the highest risk of fraud will be excluded from Federal healthcare programs to protect those programs and their beneficiaries. Excluded individuals and entities are listed in OIG's Exclusions Database.

High-Risk:  Heightened Scrutiny

  • Parties are in the High-Risk category because they pose a significant risk to Federal healthcare programs and beneficiaries. This is because, although OIG determined that these parties needed additional oversight, they refused to enter Corporate Integrity Agreements (CIAs) sufficient to protect Federal healthcare programs. Parties in the High-Risk category that reached settlements since on October 1, 2018, or later are listed here.

Medium risk:  CIAs or Corporate Integrity Agreements

  • Healthcare providers and other entities in the Medium Risk category have signed CIAs with OIG to settle investigations involving Federal healthcare programs. Under these agreements, parties promise to fulfill various obligations in exchange for continuing to participate in the programs.

Lower Risk:  No Further Action

  • The OIG sometimes concludes that parties present a relatively low risk to Federal healthcare programs. As a result, OIG is not seeking to exclude them from those programs or require a CIA. OIG's cases against these parties are closed without evaluating the effectiveness of any efforts the parties have made to ensure future compliance with Federal healthcare program requirements.

Low Risk:  Self-Disclosure

  • A party may disclose evidence of potential fraud related to Federal healthcare programs to OIG. The OIG believes that doing so in good faith and cooperating with OIG's review and resolution process generally demonstrates that the party has an effective compliance program. OIG works to resolve such cases faster, for lower settlement amounts, and with a release from potential exclusion with no CIA or other requirements. More information about OIG's self-disclosure protocol – click here.

This ends Part 3 for the denials and appeals article series. There is so much more to share with you, however, as you can see, filing an appeal involves various considerations and skill sets. Register, train and certify in Appeals Management - Online, On-Demand! 


Read More
Healthcare Revenue Cycle Compliance
Billing/RCM

Part 2: Understanding How Payers Deny Claims

Written by: AIHC Blogger


This article provides educational information related to fighting unreasonable denials by working through a complex payer appeals process. This information is not all-inclusive and the article is a truncated version of Lesson 3 from our Certified Outpatient Clinical Appeals Specialist (COCASSM) training program. The complex Medicare appeals process is used to demonstrate the importance of appealing claims denied in an audit. Make sure to read Part 1: Managing Denials is Important to Good A/R Hygiene.


Audited by a payer?  


Is your organization under a payer audit? Fight back by appealing unreasonable denials. But first, learn more about how a complex payer audit system works. 


Understanding how a payer reviews and makes a payment determination will strengthen your ability to argue and defend your claim upon appeal. The learning objective of this lesson is to help you become familiar with the Medicare Claims Review Program (MCRP). This program monitors inappropriate payments. Other payers mirror Medicare’s program.


What is an “improper” payment?

 

These are reimbursements that should not have been made or that were made in incorrect amounts. According to the U.S. Government Accountability Office (GAO), improper payments have been estimated to total almost $1.7 trillion government-wide from fiscal years 2003 through 2019. Auditing and denying claims after the claims have been paid is “big money” for the government. 

  • For example, the GAO states that they identified about $77.6 billion in financial benefits in fiscal year 2020—a return of about $114 for every $1 invested.
  • They also identified 1,332 other benefits that led to program and operational improvements across the government.
  • Most recently, GAO has been evaluating the largest response to a national emergency in US history, the $2.6 trillion COVID-19 response legislation, and making recommendations about how to improve its effectiveness in dealing with public health issues and the economy.

The Medicare Fee-for-Service Compliance programs prevent, reduce, and measure improper payments in FFS Medicare through medical review. A number of programs are provided to educate and support Medicare providers in understanding and applying Medicare FFS policies while reducing provider burden.


A Medicare contractor may use any relevant information they deem necessary to make a prepayment or post-payment claim review determination. This includes any documentation submitted with the claim or through an additional documentation request.


CMS' Center for Program Integrity (CPI) oversees Medicare medical review contractors. CPI conducts contractor oversight activities such as:

  • Providing broad direction on medical review policy
  • Reviewing and approving Medicare contractors' annual medical review strategies
  • Facilitating Medicare contractors' implementation of recently enacted Medicare legislation
  • Facilitating compliance with current regulations
  • Ensuring Medicare contractors' performance of CMS operating instructions
  • Conducting continuous monitoring and evaluation of Medicare Contractors' performance in accord with CMS program instructions as well as contractors' strategies and goals
  • Providing ongoing feedback and consultation to contractors regarding Medicare program and medical review issues

The Medicare Claims Review Program, or “MCRP,” involves both technical and clinical categories of denials performed by CMS contractors. It is a complex system, perfect to use as a teaching example! There are two categories of denials:


1. Technical Denial & Rejection
     • This topic has been covered in previous lessons, but let’s review again!

o A technical denial is an error made when filing the claim, such as lack of appropriate coordination of benefits and filing to secondary insurance first. When a critical error gets through the scrubber, the insurance payer software may reject the claim due an error. Correcting these types of errors quickly and refiling the claim typically results in payment. These claims often “fall through the cracks” and can be suspended. Lack of tending to rejected claims can cause huge revenue loss for your organization.


2. Clinical Denial
    • A clinical denial is the denial of payment by an insurance payor on the basis of medical necessity, length of stay or level of care. Special review of documentation, payer guidelines and often appealing the claim is required to obtain payment.

o When a payer sends an RFI (Request for Information), the payer is auditing the claim data against medical record documentation.
o Untimely response to the RFI will result in a denial.
o Sending inappropriate or wrong information to the payer will result in a denial.
o These types of denials can potentially trigger a larger audit, a probe, or an abuse or fraud investigation of your organization


CMS estimates the Medicare FFS improper payment rate through the Comprehensive Error Rate Testing (CERT) program. Each year, the CERT program reviews a statistically valid stratified random sample of Medicare FFS claims to determine if they were paid properly under Medicare coverage, coding, and payment rules.


Audits or claim reviews are conducted either prepayment or post-payment of the claim and typically fall under one of these categories:

  • Compliance to bundling edits (Medicare’s National Correct Coding Initiative or NCCI Edits)
  • Medically Unlikely Edits or “MUEs”
  • Comprehensive Error Rate Testing (CERT)
  • Recovery Audit Program
  • Medical Reviews (MRs)

National Correct Coding Initiative (NCCI) Edits


CMS developed the National Correct Coding Initiative (NCCI) to promote national correct coding methodologies and to control improper coding leading to inappropriate payment in Part B claims. The Centers for Medicare & Medicaid Services (CMS) owns the NCCI program and is responsible for all decisions regarding its contents.


Most payers either use the NCCI edits or have a similar bundling edit system in place. Basically, bundling edits review codes on a claim to determine whether the items can be filed and paid separately or bundled into one code.


The claims scrubber software within your practice management system will analyze the codes on the claim and compare the information to the NCCI edits. Items that should be bundled will be suspended for further review. Your office cannot bill a patient for a service denied due to denied claims based on the NCCI edits.


These edits are updated at least quarterly and revised in your practice management system through updates to the software. Information about the National Correct Coding Initiative (NCCI) can be found in the Internet-Only Manual, Publication 100-04, Section 20.9 of Chapter 23 of the Medicare Claims Processing Manual.


When appealing NCCI edit denials, it is important to review the claim to ensure the appropriate modifier has been used. If not, review the documentation and appropriately append the modifier to the line item on the claim and submit your appeal with the documentation. 


Modifiers allowed with the National Correct Coding Initiative (NCCI) procedure to procedure (PTP) edit that can be used under appropriate clinical circumstances to bypass an NCCI PTP edit include:

  • Anatomic modifiers: E1-E4, FA, F1-F9, TA, T1-T9, LT, RT, LC, LD, RC, LM, RI
  • Global surgery modifiers: 24, 25, 57, 58, 78, 79
  • Other modifiers: 27, 59, 91, XE, XS, XP, XU

NOTE:  Overuse of such modifiers just to get claims passed through the edits for payment can trigger an audit, probe or investigation. 

 

Medically Unlikely Edit (MUE)


This audit feature analyzes a claim to determine if the appropriate number of units are being reported per line item. It is a unit of service edit for a Healthcare Common Procedure Coding System (HCPCS)/Current Procedural Terminology (CPT) code for services rendered by a single provider/supplier to a single beneficiary on the same date of service (DOS).

 

The ideal MUE is the maximum unit of service that would be reported for a HCPCS/CPT code on the vast majority of appropriately reported claims. 


MUEs are designed to reduce errors due to clerical entries and incorrect coding. MUEs are adjudicated either as claim line edits or DOS edits.

  • If the MUE is a claim line edit, each line of a claim is adjudicated against the MUE value for the Healthcare Common Procedure Coding System (HCPCS)/Current Procedural Terminology (CPT) code on that claim line.
  • If the UOS on the claim line exceeds the MUE value, all UOS for that claim line are denied. If the same code is reported on more than one line of a claim by using CPT modifiers, each line of the claim is adjudicated separately against the MUE value of the code on that claim line.

For Medically Unlikely Edits (MUEs) that are adjudicated as claim line edits, each line of a claim is adjudicated separately against the MUE value for the code on that line. The appropriate use of Healthcare Common Procedure Coding System (HCPCS)/Current Procedural Terminology (CPT) modifiers to report the same code on separate lines of a claim will enable a provider/supplier to report medically reasonable and necessary UOS in excess of an MUE value.


24.G is the field on the 1500 claim being audited for MUE compliance:



These edits are updated at least quarterly and revised in your practice management system through updates to the software. 


Comprehensive Error Rate Testing (CERT) Program


CERT contractors perform a complex medical review of the claim and the supporting documentation to determine whether the claim was paid appropriately according to Medicare coverage, payment, coding, and billing rules.


CMS calculates a national Medicare Fee-For-Service (FFS) improper payment rate and improper payment rates by service type to accurately measure the performance of the MACs and gain insight into the causes of errors. CMS publishes the results of these reviews annually.


The Medicare FFS Improper Payment Rate is a good indicator of how claim errors in the Medicare FFS Program impact the Medicare Trust Fund. CERT errors are listed by the following categories:



The Recovery Audit Program


Most hospitals and clinics are familiar with the “RAC” or Recovery Audit Contractor program – now referred to as the “Recovery Audit Program” by CMS.


RAC's review claims on a post-payment basis by auditing past Medicare FFS claim data for potential overpayments or underpayments and reviewing medical records when necessary to make appropriate determinations. When performing these reviews, Recovery Auditors follow Medicare regulations, billing instructions, National Coverage Determinations (NCDs), coverage provisions, and the respective MAC’s Local Coverage Determinations (LCDs). Recovery Auditors do not develop or apply their own coverage, payment, or billing policies.


In general, Recovery Auditors do not review a claim previously reviewed by another entity. Recovery Auditors analyze claim data using their proprietary software to identify claims that clearly or likely contain improper payments.


Medical Review Audits


Medical reviews identify errors through claims analysis and/or medical record review activities. Contractors use this information to help ensure they provide proper Medicare payments (and recover any improper payments if the claim was already paid). Contractors also provide education to help ensure future compliance.


A Medicare contractor may use any relevant information they deem necessary to make a prepayment or post-payment claim review determination. This includes any documentation submitted with the claim or through an additional documentation request. 


One of the first items reviewed is a valid authentication or signature. Next, auditors typically review documentation for medical necessity; information to support units, laterality, diagnosis coding and supporting documentation such as signed orders or plan of care.


Learn more about clean claims, prompt pay laws, fighting denials based on medical necessity, appealing ERISA denials, the Medicare appeals process, and how to create an effective denials and appeals program – click here and become an Outpatient Clinical Appeals Specialist. Click Here to see if we have any upcoming classroom training camps!

Read More
HIPAA Compliance
HIPAA

Healthcare Apps and Data Privacy/Security Risks

Written by Susan Walberg, JD MPA CHC




Healthcare apps have become increasingly prevalent, with people using them for counting steps, monitoring their calories, or linking to various medical devices, to name just a few examples. Since the COVID outbreak, however, and the explosion of telehealth as a healthcare option, these apps have proliferated at an insane rate. As of 2020, there were 325,000 healthcare apps on the market, with more coming all the time.


Whether you are a consumer who uses such apps, or a provider who wants to develop an app for patients to use, it’s important to understand some of the privacy and security risks that may accompany the use of such tools and what to watch out for.


What Are Healthcare Apps?


An ‘app’ is a small program that can be loaded onto a phone or mobile device to perform a specialized function. There are two main types of healthcare apps in terms of privacy and security regulations, and the rules governing them vary accordingly.


The first type are the applications that are used by your healthcare provider. They may be used to store your lab or radiology results or might be integrated with a medical device for tracking/monitoring purposes, such as an electrocardiography device that monitors heart activity. Or they may be used to coordinate your care.


The second type are personal or private healthcare apps, those that an individual can get at an app store to track and manage their diet, exercise, or specific health conditions. There are apps for mental health, diabetes, and, of course, COVID, to name just a few. Many of these apps are free.


Nothing in Life Is Free


First, let’s talk about those ‘free’ apps.


Free apps, how cool is that? Depending on your view, an application that tracks and shares your personal information might not really be ‘free’.


If you go online and look for a free app to help you count calories or manage your diet, for instance, the odds are good that there are advertisements on the app, right? Well, most of those ‘free’ apps, with the ads included, will be sharing your information with the advertisers and perhaps even with other companies, such as the ‘big tech’ companies or other stakeholders or investors.


You may expect this, and you might not care. After all, any online Google search leads to targeted Facebook ads relating to that same subject matter, as many of us have noticed. We may not like it, but we are getting used to the fact that our online activity is not really private.


But when you choose one of those apps, think about what information you are entering, because it is probably not private. How much of your medical information is being collected in order to help you manage your diabetes or exercise program? And do you know where that information might be shared? You may accept the fact that your use of the app is not private, just like your Google searches seem to have a direct pipeline to Facebook. But think about the data collected, because that’s not private either. And that’s not illegal in this situation.


But…But…HIPAA


How can this health information NOT be private? There must be regulations protecting your privacy, especially when it comes to your healthcare information, right? We hear all the time about HIPAA (The Health Insurance Portability and Accountability Act of 1996) and how your health information can’t be shared.


Just to be clear, in a nutshell, HIPAA only applies to those apps that are used and offered by your healthcare provider or insurance company (or some similar organization that is regulated by HIPAA). Those organizations are subject to the HIPAA Privacy and Security regulations (as well as the HITECH and Omnibus laws that followed), so any product they offer in conjunction with their regulated services would typically be subject to the same laws. This does not mean that if your doctor tells you there are apps in the marketplace to monitor your diabetes that they would be subject to HIPAA. But if your insurance company, for instance, offers you a tool as part of your plan that will help you manage a chronic health condition, HIPAA would generally apply. You may not be sure, so it’s important to ask.


If the app is, indeed, regulated under HIPAA, that means that privacy and data security controls must be in place. There should be a privacy/security policy that you can review, and you have specific rights with respect to your information and how it’s used. There are limitations around, for instance, how your data can be used or shared for marketing purposes. It also means that there must be a designated privacy and security ‘official’ who has oversight of compliance with these regulations. A company that provides a healthcare app to physician practices, insurance companies, or similar organizations would be considered a ‘Business Associate’ of that provider or insurance company, which means they are subject to the same requirements. HIPAA does provide a broad range of protections, but they are limited to those specific scenarios.


The reality is that few laws govern the privacy of information you voluntarily share in one of these publicly-available apps, so if you go online and pick an app to track or monitor your own health condition or information…most are not subject to privacy laws.


Apps Provided by Your Physician, Insurance Company, Etc.


The apps used by your doctor’s office or insurance company are subject to much tighter regulation, but also often contain more personal data. Especially with the increased use of telehealth services, provider’s offices are relying on various applications and platforms to facilitate the provision of healthcare services. These apps, and the companies that offer them, are covered under HIPAA as ‘Business Associates’ of the provider or insurance company if the app uses, stores, or transmits patient health information on behalf of the healthcare organization.


Due to COVID, the government has loosened up the privacy regulations in order to allow greater flexibility in providing telehealth services. While this is good news for providers and the patients needing those services, it also means more potential risk to protected health information (PHI). It’s important to keep in mind that, in addition to whatever information you enter online, a telehealth application likely has requested permission to access your calendar, camera, and microphone.


The good news is that, although providers may have been using some of the less secure apps in the beginning of COVID, just out of necessity, those providers who plan to continue providing telehealth services are working to ensure compliance with privacy and security requirements. App developers are busy developing apps to accommodate this changing market, and compliance is a top concern.


Apps as Mobile Devices


There is one type of application which is actually considered by the Food and Drug Administration (FDA) to be a medical device, in addition to being covered under HIPAA (because they are provided in conjunction with healthcare services). Those are the apps that are intended to be used ‘for the diagnosis of disease or other conditions, or the cure, mitigation, treatment, or prevention of disease, or is intended to affect the structure or any function of the body of man’ under section 201(h) of the Food, Drug, and Cosmetic Act. In general, if the purpose or function of the app is to assist in performing a medical device function, it will be treated as a medical device under the FDA. For instance, if the app can be run on a smart phone or other hand-held device and analyzes and interprets EKG waveforms to monitor cardiac irregularities, it would be considered analogous to those software programs that perform the same function and are otherwise regulated as a medical device.


The intent of the FDA is to ensure patient safety related to the use of those devices that could compromise or risk patient health. This oversight is limited to those devices marketed and offered to perform these medical device functions.


Although the FDA purview is not privacy or data security, the FDA jurisdiction is noteworthy in terms of regulatory oversight. For purposes of HIPAA, these devices would typically be subject to the Privacy and Security rules as they are used in conjunction with your provider or insurance company, as discussed above.


How Do You Know if Your Data Is Secure?


Apps in the marketplace that are available to help track health-related information should have a privacy policy, although at the current time it is not required by law for apps that are not considered a medical device or are subject to HIPAA. It is highly recommended that you find those policies and read them, even though some may be lengthy and not written clearly (might be overly technical or legalistic).


Even if the apps have privacy policies, those policies might not be easy to find, and you might discover that the policy does state the ways in which they do share your information. There is no law against the sale or disclosure of data from independent apps to third parties and those apps are being funded somehow (data is valuable). In addition to data sharing, the privacy policy should explain how it safeguards your data. There should be information security measures in place to prevent breaches of your data. And lastly, even if the privacy policy sounds good, the app developer may not necessarily follow their own policies. This is not to say that an app developer is deliberately being deceptive; a developer or their sponsoring company may adopt a policy from another app they are familiar with or may bring in a consultant to write their policy, but the specific terms in the policy aren’t implemented during development. It can happen. And this isn’t limited to app developers; any organization can fall short of following its own policies. Many app developers have a technical or clinical background and may not fully understand the healthcare regulatory framework.


You can also check an app’s automatic settings and look for those that impact privacy, such as location tracking. Beware, though, that in some instances turning those options off will make it more difficult to use the app.


The bottom line here is caveat emptor…buyer beware. Especially if you’re not ‘buying’ and it’s ‘free’.


How Can Data Be Compromised?


Even when providers, insurance companies, and app developers are focused on compliance with the various privacy and security requirements, PHI can still be compromised, but it is less likely. Common mishaps occur in a number of ways:

  • Employee errors. Human errors can occur in any setting. It can be an employee discussing patient information out loud in a non-private setting, clicking on a link that allows a virus or ransomware attack, or accidentally entering an incorrect phone number and sending information to the wrong person. This isn’t limited to technology-related issues but privacy in general.
  • Poor access controls. There needs to be a solid process, that is followed religiously, to ensure that only individuals who need access are given access, and that former employees or business associates are promptly removed when they no longer have a need for access. This also includes business partners who have employees who need access in order to provide services to another company or practice. These employees need their own access, not a universal access that cannot be tracked.
  • Failure to monitor. Any organization that maintains PHI electronically should have a process for routinely reviewing who is accessing sensitive information and following up on any questionable access. Audit trails are part of any good security structure.
  • Failure to securely store data. Not only should data be stored in a secure manner, it should also be consistently destroyed/removed when applicable retention periods have expired.
  • Inadequate encryption.
  • Workstation and device security. Applications should time-out when not in use, rather than rely on users to remember to do so.
  • Failure to conduct a comprehensive risk assessment that includes the various apps and networked devices where PHI is stored or transmitted.
  • Increased remote workers. Employees working from home are more likely to use personal devices that don’t have proper levels of encryption and that are, by definition, less private due to the offsite location. Access is much harder to control and networks may not be secure.

The above issues do not pertain only to apps, but in general to information privacy and security, especially in the new era of increased telehealth services. Those issues are also the types of failures HIPAA was designed to prevent and would likely be considered violations, depending on the specific facts. If you are considering using an app or electronic platform where personal information will be entered, it’s recommended that you ask your provider or insurance company who is offering this tool what their privacy and security policies are. If their organization is using and recommending such a tool, they have almost certainly done the review of privacy and security controls. And if you are a provider considering using an app, or an app developer, the above list is for you. You should have designated ‘privacy and security officials’ who ensure the above risk areas are addressed.


What Are the Risks?


Most people care about the privacy of their health information just because it’s private and not other people’s business. But there are actual risks to consider, which users of these apps should understand:

  • Data is shared with third parties for sales and marketing, increasing the targeting of ads you receive.
  • Even information that is supposedly ‘de-identified’ can include enough information to make users identifiable, and it may be very sensitive information, for instance relating to mental health or substance abuse.
  • Medical identity theft, which can result in someone using your identity to receive free healthcare services or to file fraudulent claims. Healthcare data is valuable for those reasons, which is why it is often targeted by hackers.
  • Additional outside companies, such as Facebook or Google, may acquire the information and build user profiles. Once the information is out there in that environment, there is little control over it and it’s difficult to know who could access it or how it could be used.
  • Your PHI could be acquired by insurance companies or other healthcare companies that could use it against you in underwriting or pricing determinations. Who else would you not want knowing your private information? An employer? The possibilities are frightening, especially considering that once the information is out there, it’s out there. You can’t put the genie back in the bottle.

Conclusion


Telemedicine and the use of online applications has exploded in recent years, particularly in relation to the COVID pandemic and the resulting changes in the delivery of healthcare. The regulatory framework has not necessarily caught up to technology yet, so while HIPAA laws apply to some applications, many that are out there being used by consumers are not regulated in terms of protecting sensitive information. Health information can be bought and sold in the marketplace, it has a value for advertisers, thieves, and others.


For consumers, just be aware of the potential risks before you start using an app; check the app’s privacy and security policies and consider carefully what information you are comfortable exposing. If the app comes from your provider or insurance company, ask about the security controls and how they are protecting your data.


For providers, consider your own liability in terms of recommending an app and make sure your organization has done its due diligence to ensure proper security measures are in place. You should have your own privacy and security experts evaluate the tool before offering it to patients.


For app developers, be aware that technical security isn’t your only concern; you will want to have assistance from someone with healthcare privacy and security regulatory expertise. This will be something that potential clients and investors will be asking about.


Susan Walberg is a healthcare consultant who works with providers and healthcare start-ups. She can be reached at https://www.susanwalberg.com/

Read More