In a recently released white paper titled “The Nation’s Challenge to Combat Durable Medical Equipment Fraud in Medicare,” HHS Office of Inspector General details three fraud vectors it says are fueling Medicare’s crackdown on durable medical equipment suppliers.
The report lands as CMS suspends billions of dollars in suspect DME payments, freezes new supplier enrollment and backs a growing list of prosecutions against DME companies and the physicians tied to them.
While ASCs don’t bill Medicare directly for DME, the physicians who operate in them write DME orders, sign paperwork and maintain referral relationships — activity OIG identifies as one of the three fraud vectors now driving federal enforcement.
OIG’s report argues that nearly every large-scale DME fraud scheme depends on the same three ingredients: a Medicare-enrolled supplier, a physician order and a beneficiary’s identifying information. Criminal networks have gotten efficient at obtaining all three, the report says, sometimes at a scale that dwarfs typical healthcare fraud cases. Operation Gold Rush, a transnational scheme OIG cites as illustrative of the threat, billed Medicare more than $10 billion and collected $941 million from Medicare and secondary payers before it was shut down.
On the supplier side, OIG found that criminals routinely use straw owners to obscure who actually controls a DME company, file unreported ownership changes to dodge scrutiny, and exploit the fact that Medicare still accepts paper enrollment applications. The agency is calling for CMS to require unannounced site inspections, use artificial intelligence and data analytics to catch unreported ownership changes, and eliminate paper enrollment altogether. OIG also flagged the $50,000 surety bond suppliers must post — unchanged since it was introduced in 2009 — as overdue for an update.
The second vector runs through physician orders — the most directly relevant to ASC leadership. OIG documented schemes built on fabricated physician orders, kickbacks paid to physicians willing to sign off on unnecessary equipment, physicians tricked into signing pre-filled orders for patients they never examined, and stolen physician identification numbers used without a physician’s knowledge. To close the gap, OIG is calling on CMS to build an electronic system physicians can use to verify their own orders, expand pre-payment medical review, and explore artificial intelligence tools capable of flagging AI-generated fraudulent documentation.
The third vector is beneficiary identity theft: enrollee identification numbers obtained through health data breaches, purchased on the dark web or social media, or harvested through phone and text scams targeting Medicare enrollees directly. OIG wants CMS to lock down or discontinue enrollee lookup tools, extend existing bans on unsolicited outreach to text, email and other digital channels, and partner with social media platforms to curb identifier trafficking.
One gap OIG singles out deserves particular attention from ASC-affiliated physicians and administrators who work with Medicare Advantage plans: DME suppliers that only serve Medicare Advantage enrollees currently aren’t required to enroll in traditional Medicare at all, which OIG says leaves a screening blind spot outside CMS’ usual oversight.
CMS Administrator Mehmet Oz, MD, responded to the report on July 23, pointing to steps the agency has already taken. Its Fraud Defense Operations Center — CMS has branded it the “Medicare War Room” — launched in March 2025 and suspended $2.1 billion in potentially fraudulent payments in its first year, over $1.9 billion of it tied to suspect DMEPOS billing. CMS also cited $41.9 billion in program integrity savings for fiscal year 2025, up 59% from $26.3 billion the year before, along with a six-month moratorium on new DME enrollment imposed in February 2026 and a publicly posted list of revoked Medicare enrollments released in March 2026.
Dr. Oz’s response, however, describes most of OIG’s specific recommendations — the enrollment overhaul, the physician order-verification system, the beneficiary protections — as still “under consideration” for a forthcoming rule CMS is calling the “CRUSH Rule.” For now, the enforcement pressure is running ahead of the regulatory fix.
For ASC compliance officers, the practical takeaway sits in the physician-order vector. Any physician who signs DME orders, refers patients into a DME supplier relationship, or operates within a Medicare Advantage referral network is standing inside the exact fraud pattern OIG says federal investigators are now built to find. The enrollment moratorium and the promised order-verification system are both worth tracking closely, since either could reshape how DME orders tied to ASC procedures get documented and verified going forward.
At the Becker’s 32nd Annual Meeting: The Business and Operations of ASCs, taking place October 29-31 in Chicago, ASC leaders, surgeons and healthcare executives will explore strategies to drive growth, enhance operational performance, navigate reimbursement challenges and prepare for the future of ambulatory surgery. Apply for complimentary registration now.
