Increased Federal Scrutiny in Blue Cities: What Health & Human Services Providers Must Do Now to Protect Medicaid Funding


If you run a health or human services organization in Philadelphia, now is probably a good time to take another look at your billing and compliance practices. The federal government is paying more attention to Medicaid fraud, waste, and abuse, and Philadelphia is now part of that picture.
The Justice Department recently announced the expansion of the Northeast Health Care Fraud Strike Force into the Eastern District of Pennsylvania. DOJ's message was pretty direct. The department said the move was intended to send “a clear message to fraudsters in the region” and that it would use “all available tools to protect Medicaid.”
For providers, that should be a wake-up call.
This does not mean that every billing mistake is going to turn into a federal investigation. It does mean, however, that providers should not assume that billing problems are going to remain an internal matter, particularly when there is a pattern or when the organization has failed to address obvious warning signs.
That is especially important for home and community-based services, waiver programs, behavioral health providers, and other human services organizations that rely heavily on direct care staff.
Philadelphia Is Now on the Strike Force's Radar
The expansion of the Northeast Health Care Fraud Strike Force into Philadelphia is more than a press release. These investigations can bring together federal prosecutors and agencies including the FBI, HHS Office of Inspector General, DEA, and IRS. Investigators also have access to large amounts of data that can be used to identify billing patterns that do not make sense.
The recent DOJ announcement gives some pretty striking examples: In cases described by the department, providers billed Medicaid for services provided by direct care workers while they were incarcerated or out of the country. In another situation, providers allegedly billed for services provided by a single direct care worker that totaled more than 24 hours in a single day. Obviously, those are extreme examples.
However, providers should pay attention to what they tell us about how these investigations work. The government does not have to rely solely on a reviewer sitting down and reading a stack of timesheets. It can compare billing data with payroll records, employment information, EVV records, location information, and other sources of data.
When those records don't line up, someone is eventually going to have to explain why.
Human Services Providers Have Some Particular Vulnerabilities
Most human services organizations are not trying to commit fraud. The problem is that many of them operate in an environment where mistakes and abuse can be difficult to catch. There may be hundreds of direct care employees working in clients' homes or out in the community. Turnover can be high. Supervisors may be responsible for large numbers of employees. And much of the work happens outside the agency's physical office. Usually, administrative staff like HR and compliance are overworked and understaffed. That makes oversight so much harder.
It also means providers need to be realistic about where their risks are. A provider shouldn't assume that an employee who submits a questionable timesheet is the only person who could have a problem. Investigators may eventually ask what the organization knew, what its supervisors were doing, and whether anyone should have noticed the problem sooner. In other words, when you found one case of fraud, what did you do to ensure it wasn’t systemic, and what measures did you take to guard against future fraud.
If one employee makes an isolated mistake, that's one thing. If the same employee has been submitting questionable claims for six months and nobody has looked at them, the issue becomes much harder to explain. If the DOJ looks at the providers records and spot patterns of fraud that should have been obvious to the provider, that can be devastating.
Start With the Basics: Did the Service Actually Happen?
The most important question a provider should be able to answer is a simple one:
Did we Actually Provide the Service we billed Medicaid for?
Every billed unit should have documentation behind it. That means providers should be regularly comparing billing information against the records that are supposed to support the claim, including:
EVV records, where applicable;
clock-in and clock-out information;
payroll records;
service plans and authorized hours;
employee schedules;
progress notes or other service documentation; and
location information, when the system captures it.
When the billing documentation was created, how often it was modified and why.
It is also important to look at exceptions. An occasional missed punch or documentation error is not necessarily a major compliance problem. But when the same employee has repeated EVV exceptions, unusually high hours, excessive overtime, or documentation that consistently doesn't line up, someone should be asking questions. Someone should be investigating, someone should be holding noncompliant staff accountable, someone should be tweaking policies and procedures to ensure they cover these fraud alert triggers.
Supervisors Can't Just Sign Off and Move On
One area to pay particular attention to is supervision. A supervisor's job cannot simply be to approve whatever shows up on a timesheet. Supervisors should be looking for obvious problems. Is the employee actually available during the hours being billed? Are two shifts overlapping? Is the employee claiming more hours than could reasonably have been worked? Does the payroll record support the hours being billed?
There are plenty of legitimate explanations for unusual situations. But somebody needs to notice the unusual situation and find out what happened. In our experience, community care providers who have engaged in fraudulent activity usually had supervisors who were not paying attention, or otherwise providing the oversight that the provider expected.
The DOJ has pointed to cases involving direct care workers who allegedly billed Medicaid while driving for rideshare services, attending court hearings, or working construction jobs. In our experience we have discovered instances where the community worker was submitting documentation for services rendered by two different providers to different clients AT THE SAME TIME. It’s incumbent upon providers to understand where their employees are moonlighting, what they’re doing, and when they work for other employers.
Internal Audits Should Be Looking for Patterns
A good compliance program isn't just about having policies sitting in a binder.
Someone needs to actually look at the data. Providers should consider conducting regular audits of employees who have things like:
unusually high service hours;
significant overtime;
repeated EVV exceptions;
frequent schedule changes;
unavailability during the workday;
documentation problems; or
other unusual billing patterns.
The goal isn't to assume that these employees are doing something wrong; but to identify situations that deserve a closer look.
For providers that use family members as caregivers, random quality-control calls can also be useful. A provider can call the client's number during a scheduled shift and, when appropriate, confirm that the caregiver is actually there by speaking to them on the client’s landline.
Outside employment deserves attention, too. If an employee is working another full-time job, driving for a rideshare company, or regularly working other jobs during the same hours they are reporting Medicaid-funded services, the agency should know about it. If you have a community worker who also works overnights (in an awake position) during their workweek, at best, you have an employee who cannot give your clients their best, at worst, you have an employee who is inflating the time on their service documents so they can get some sleep during the day.
This doesn't mean employees can't have second jobs. It means the provider needs enough information to determine whether the outside employment creates a legitimate scheduling or billing conflict. This is where your policies and procedures intersect, where HR and Compliance work together to ensure the right policies, training, onboarding and procedures exist to ensure billing integrity, maximize client satisfaction and increase employee retention.
Home Healthcare Agencies (HHA) have unique challenges with the family member caregiver dynamic. HHAs need to be particularly diligent with family member caregivers simply because the client will often cover up for them when they don’t provide services authorized. We have discovered instances where the provider was paying employment taxes based on an out-of-state domicile (Arizona) for services provided on the east coast purportedly on a daily basis. When the provider found this discrepancy and called the client to speak with the caregiver, the client repeatedly stated that the caregiver was in the bathroom, or was taking trash out. A couple of minutes later the caregiver would call from her cell phone. When confronted on it, the client alleged that the caregiver’s daughter was actually providing the services—the daughter was not certified as a home health caregiver—this resulted in a chargeback for almost six months of services. In another instance, the caregiver was evv-compliant, but always from directly outside the client’s home, not inside. Further research revealed that the client had not lived at the address on file for several months and when the caregiver was questioned on the client’s location, he admitted the client had moved to Florida some months back.
And don't overlook the simple stuff. Compare billing to payroll. If you billed Medicaid for 40 hours of direct care, there should be a payroll record showing that the employee worked those hours. Check the listed domicile of all your community workers to ensure they are in commuting distance to where they are supposed to be providing services. It sounds obvious. But basic controls are often where problems are first identified.
What If You Actually Find a Problem?
This is where things can get complicated. Not every overpayment is fraud, and not every documentation error requires a federal self-disclosure, particularly if you can reverse the overpayment.
But providers do have obligations under federal and state law concerning identified overpayments and potential fraud. The specific requirements depend on the circumstances and the Medicaid program involved.
So if an organization discovers fabricated timesheets, services that were never provided, unauthorized services, falsified documentation, EVV manipulation, billing that doesn't match payroll, or claims submitted while a client was hospitalized or otherwise unavailable, management should not simply correct the next claim and move on. The issue should be escalated.
The organization needs to determine what happened, how long it went on, whether other claims are affected, how much money may be involved, and whether reporting or repayment obligations apply. That is the point where experienced compliance and legal counsel can be particularly important. The key is to have a process before the problem happens.
Don't Wait for an Investigator to Find It First
One of the biggest mistakes a provider can make is assuming that a problem is too small for anyone outside the organization to notice. That may have been a safe assumption years ago. It is much harder to make today. Medicaid claims generate a tremendous amount of data. Federal and state agencies can compare information in ways that were not practical in the past. With electronic health records, agencies can examine audit trails on every examined note to identify suspicious behavior. Artificial Intelligence lets agencies examine your data in ways you probably can’t anticipate or guard against. Remember, Agencies have access to industry-wide billing data—they can see anomalies based on averages across multiple providers. What might be normal for you may be anomalous for your region, metro area or industry.
An employee who appears to have worked an impossible number of hours, phantom services billed for a hospitalized client, EVV noncompliance outside a certain range, or billing that repeatedly conflicts with another provider’s billing can create a pattern.
Once that pattern exists, it may not matter that nobody at the organization intended to commit fraud. The provider still has to explain what happened and what it did after the problem was identified.
The primary reason you want to find any overpayment first, and report it, is because there are devastating financial and legal consequences if an Investigator finds it first. When you self-report, your repayment is usually limited to the original overpayment (sometimes with interest). But if an agency auditor finds it first, they might extrapolate that finding across your agency over a longer period than the identified fraud existed. You may also be liable for treble damages and other statutory fines. In extreme cases, provider leadership may face criminal charges and debarment.
The Bottom Line
The message coming out of Washington is pretty clear: Medicaid fraud enforcement is going to receive attention and resources. Philadelphia providers should take that seriously.
But the answer isn't to panic every time someone misses a clock-in or makes a documentation mistake. It is to have good systems, use them consistently, investigate recurring problems, and take corrective action when something doesn't look right.
At a minimum, providers should be able to answer five questions:
· Was the service authorized?
· Was the documentation that supports billing created contemporaneously with the service?
· Was the service actually provided?
· Does the content of the documentation support the services billed?
· And, if something went wrong, did we identify it and respond appropriately?
If the answer to those questions is yes, the organization is in a much better position to defend its billing.
If the answer is no—or if management isn't sure—that’s a good reason to start looking now.
It is much better to find a problem through an internal audit than to find out about it through a federal subpoena.
If your organization is unsure whether its billing, documentation, EVV, supervision, or internal audit practices would withstand scrutiny, now is the time to address the risk. Our legal team works with health and human services providers to assess compliance systems, investigate potential overpayments, strengthen policies and procedures, and respond when problems arise. Contact us to schedule a confidential consultation before a routine compliance issue becomes a government investigation.



Comments