E.6 Draft PIM Chapter 4.docx
DOCX document 599 KB Posted
- Attached to
- Unified Program Integrity Contract (UPIC) Federal contract opportunity
- Solicitation number
- HHSM-500-2015-RFP-0122
About this file
E.6 Draft PIM Chapter 4
View the file
Other files for this federal contract opportunity
Show all 50
Unified Program Integrity Contract (UPIC) has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Medicare Program Integrity Manual Chapter 4 - Program Integrity
Table of Contents (Rev.)
Transmittals for Chapter 4
4.1 - Introduction
4.1.1 - Definitions
4.2 - The Medicare Fraud Program
4.2.1 - Examples of Medicare Fraud
4.2.2 - Zone Program Integrity Contractor
4.2.2.1 - Organizational Requirements
4.2.2.2 - Liability of Zone Program Integrity Contractor - Employees
4.2.2.3 – Anti-Fraud Training
4.2.2.3.1 - Training for Law Enforcement Organizations
4.2.2.4 - Procedural Requirements
4.2.2.4.1 - Maintain Controlled Filing System and Documentation
4.2.2.4.2 - File/Document Retention
4.2.2.5 – Reserved for Future Use
4.2.2.5.1 – Reserved for Future Use
4.2.2.5.2 – Reserved for Future Use
4.2.2.6 – Program Integrity Security Requirements
4.3 - Medical Review for Program Integrity Purposes
4.4 - Other Program Integrity Requirements
4.4.1 - Requests for Information from Outside Organizations
4.4.1.1 - Reserved for Future Use
4.4.2 - Zone Program Integrity Contractor Coordination With Other Zone Program Integrity Contractors
4.4.2.1 - Zone Program Integrity Contractor Coordination With Other Entities
4.4.3 - Reserved for Future Use
4.5 – Reserved for Future Use Exhibit E.6 HHSM-500-2015-RFP-0122 UPIC
4.6 - Complaints
4.6.1 - Definition of a Complaint
4.6.2 - Complaint Screening
4.6.2.1 – Zone Program Integrity Contractor Responsibilities
4.6.3 – Screening Leads
4.6.4 - Vetting Leads with CMS
4.7 - Investigations
4.7.1 - Conducting Investigations
4.7.2 – Closing Investigations
4.8 - Disposition of Cases Referred to Law Enforcement
4.8.1 – Reversed Denials by Administrative Law Judges on Open Cases
4.8.2 - Production of Medical Records and Documentation for an Appeals Case File
4.9 - Incentive Reward Program
4.9.1 - Zone Program Integrity Contractor Responsibilities for the Incentive Reward Program
4.9.2 - Guidelines for Processing Incoming Complaints 4.9.3 - Guidelines for IRP Complaint Tracking
4.10 - Fraud Alerts
4.10.1 - Reserved for Future Use
4.10.2 - Reserved for Future Use
4.10.3 - Reserved for Future Use
4.10.4 - Reserved for Future Use
4.10.5 - Reserved for Future Use
4.11 - Fraud Investigation Database Entries
4.11.1 - Background
4.11.1.1 - Information Not Captured in the FID
4.11.1.2 – Entering OIG Immediate Advisements into the FID
4.11.1.3 - Documentation of Identity Theft and Compromised HICNs in the FID
4.11.2 – Investigation, Case, Payment Suspension Entries, and Requests for Information Entries
4.11.2.1 - Initial Entry Requirements for Investigations
4.11.2.2 – Initial Entry Requirements for Cases Referred to Law Enforcement
4.11.2.3 – Initial Entry Requirements for Durable Medical Equipment, Prosthetics, Orthotics, and Supplies Payment Suspensions
| 4.11.2.3.1 - Initial Entry Requirement for Non-Durable Medical Equipment, Prosthetics, Orthotics, and Supplies Payment Suspensions | 4.11.2.3.2 - Initial Entry Requirements for Requests for Information and Requests for Assistance | |||
| 4.11.2.4 – Update Requirements for Investigations 4.11.2.5 – Update Requirements for Cases 4.11.2.6 – Update Requirements for National Durable Medical Equipment, Prosthetics, Orthotics, and Supplies Payment Suspensions | 4.11.2.6.1 - Update Requirements for Non-Durable Medical Equipment, Prosthetics, Orthotics, and Supplies Payment Suspensions | 4.11.2.6.2 - Update Requirements for Requests for Information and Requests for Assistance | ||
| 4.11.2.7 – OIG Non-Response to or Declination of Case Referral 4.11.2.8 – Closing Investigations | 4.11.2.9 – Closing Cases Referred to Law Enforcement 4.11.2.10 – Removing Payment Suspensions |
4.11.2.10.1 - Closing Requests for Information and Requests for Assistance
4.11.2.11 – Duplicate Entries 4.11.2.12 – Deleting Investigations, Cases, or Suspensions
4.11.3 - Operational Issues
4.11.3.1 - Access
4.11.3.2 - The Fraud Investigation Database User’s Group
4.11.3.3 – Zone Program Integrity Contractor Fraud Investigation Database Contractor System Administrator
4.11.3.4 - The Fraud Investigation Database Mailbox
4.12 - Reserved for Future Use
4.12.1 – Reserved for Future Use
4.12.2 - Reserved for Future Use
4.12.3 - Reserved for Future Use
4.12.4 - Reserved for Future Use
4.13 - Administrative Relief from Program Integrity Review in the Presence of a Disaster
4.14 – Provider/Supplier Contacts by the Zone Program Integrity Contractor
4.16 – MAC and ZPIC Coordination on Voluntary Refunds
4.17 – Reserved for Future Use
4.18 - Referral of Cases to Other Entities for Action
4.18.1 - Referral of Cases to Office of the Inspector General/Office of Investigations
4.18.1.1 – Reserved for Future Use
4.18.1.2 - Immediate Advisements to the OIG/OI
4.18.1.3 – Payment Suspension
4.18.1.4 - OIG/OI Case Summary and Referral
4.18.1.5 - Refer to Other Law Enforcement Agencies
4.18.2 - Referral to State Agencies or Other Organizations
4.18.3 – Zone Program Integrity Contractors and Quality Improvement Organizations
4.19 - Administrative Sanctions
4.19.1 - The Zone Program Integrity and Medicare Administrative Contractor’s Role
4.19.2 - Authority to Exclude Practitioners, Providers, and Suppliers of Services
4.19.2.1 - Basis for Exclusion Under §1128(b)(6) of the Social Security Act
4.19.2.2 - Identification of Potential Exclusion Cases
4.19.2.3 - Development of Potential Exclusion Cases
4.19.2.4 - Contents of Sanction Recommendation
4.19.2.5 - Notice of Administrative Sanction Action
4.19.2.5.1 - Notification to Other Agencies
4.19.2.6 - Denial of Payment to an Excluded Party
4.19.2.6.1 - Denial of Payment to Employer of Excluded Physician
4.19.2.6.2 - Denial of Payment to Beneficiaries and Others
4.19.3 - Appeals Process
4.19.4 - Reinstatements
4.19.4.1 - Monthly Notification of Sanction Actions
4.20 - Civil Monetary Penalties
4.20.1 - Background
4.20.1.1 - Basis of Authority
4.20.1.2 - Purpose
4.20.1.3 - Enforcement
4.20.1.4 - Administrative Actions
4.20.1.5 - Documents
4.20.2 - Civil Monetary Penalty Authorities
4.20.2.1 - Civil Monetary Penalties Delegated to CMS
4.20.2.2 - Civil Monetary Penalties Delegated to OIG
4.20.3 - Referral Process
4.20.3.1 - Referral Process to CMS
4.20.3.2 - Referrals to OIG
4.20.4 - CMS Generic Civil Monetary Penalty Case Contents
4.20.5 - Additional Guidance for Specific Civil Monetary Penalties
4.20.5.1 - Beneficiary Right to Itemized Statement
4.20.5.2 - Medicare Limiting Charge Violations
4.21 - Monitor Compliance
4.21.1 - Resumption of Payment to a Provider - Continued Surveillance After Detection of Fraud
4.22 - Anti-Kickback Statute Implications
4.22.1 - Marketing to Medicare Beneficiaries
4.22.2 - Cost-Based Payment (Intermediary and Medicare Administrative Contractor Processing of Part A Claims): Necessary Factors for Protected Discounts
4.22.3 - Charge-Based Payment (Intermediary and Medicare Administrative Contractor Processing of Part B Claims): Necessary Factors for Protected Discounts
4.22.4 - Risk-Based Provider Payment: Necessary Factors for Protected Discounts
4.23 - Identity Theft- Physicians
4.24 – Reserved for Future Use
4.25 - Participation Agreement and Limiting Charge Violations
4.26 - Supplier Proof of Delivery Documentation Requirements
4.26.1 - Proof of Delivery and Delivery Methods
4.26.2 – Proof of Delivery Exceptions
4.27 –Reserve for Future Use
4.28 - Joint Operating Agreement
4.29 - Reserved for Future Use
4.30 – Reserved for Future Use
4.31 – Vulnerabilities
4.32 - Reserved for Future Use
4.33 – Zone Program Integrity Contractor Coordination with Recovery Auditors (RA)
4.34 - Suppression and/or Exclusion – Examples
For this entire chapter, until such time as all Zone Program Integrity Contractors (ZPICs) are awarded, any reference to ZPICs shall also apply to Program Safeguard Contractors (PSCs), unless otherwise noted. All references to ZPICs shall also apply to UPICs unless otherwise specified in the UPIC SOW. Medicare Administrative Contractors (MACs) shall follow the Program Integrity Manual (PIM) in accordance with their Statement of Work (SOW).
4.1 - Introduction (Rev.)
The Program Integrity Manual (PIM) reflects the principles, values, and priorities of the Medicare Integrity Program (MIP). The primary principle of program integrity (PI) is to pay claims correctly. To meet this goal, Zone Program Integrity Contractors (ZPICs) and Medicare Administrative Contractors (MACs) must ensure that Medicare pays the right amount for covered and correctly coded services rendered to eligible beneficiaries by legitimate providers. The Centers for Medicare & Medicaid Services (CMS) follows four parallel strategies in meeting this goal:
1. Prevent fraud through effective enrollment and education of providers/suppliers and beneficiaries;
2. Encourage early detection (through, for example, the Fraud Prevention System (FPS), medical review (MR) and data analysis);
3. Coordinate closely with partners, including other ZPICs, MACs, law enforcement agencies, and State Program Integrity units; and
4. Enact fair and firm enforcement policies.
The ZPICs shall follow the PIM to the extent outlined in their respective task orders SOW. The ZPICs shall only perform the functions outlined in the PIM as they pertain to their own operation. The ZPICs, in partnership with CMS, shall be proactive and innovative in finding ways to enhance the performance of PIM guidelines.
4.1.1 - Definitions (Rev.)
To facilitate understanding, the terms used in the PIM are defined in PIM Exhibit 1. The acronyms used in the PIM are listed in PIM Exhibit 23.
4.2 - The Medicare Fraud Program
This section applies to ZPICs and MACs, as indicated.
The primary goal of the ZPIC is to identify cases of suspected fraud, waste and abuse, develop them thoroughly and in a timely manner, and take immediate action to ensure that Medicare Trust Fund monies are not inappropriately paid. Payment suspension and denial of payments and the recoupment of overpayments are examples of the actions that may be taken. Following communication with the Office of Inspector General (OIG), and as appropriate, cases where there is potential fraud are referred to the OIG/Office of Investigations (OI) field office for consideration and initiation of criminal or civil prosecution, civil monetary penalties, or administrative sanction actions.
Preventing and detecting questionable or improper practices involves a cooperative effort among beneficiaries; ZPICs; MACs; providers/suppliers; quality improvement organizations (QIOs); state Medicaid fraud control units (MFCUs); state Medicaid Program Integrity units; and federal agencies such as the Centers for Medicare & Medicaid Services (CMS); the Department of Health and Human Services (HHS); the OIG; the Federal Bureau of Investigation (FBI); and the Department of Justice (DOJ).
Each investigation is unique and shall be tailored to the specific circumstances. These guidelines are not to be interpreted as requiring the ZPICs to follow a specific course of action or establish any specific requirements on the part of the government or its agents with respect to any investigation. Similarly, these guidelines shall not be interpreted as creating any rights in favor of any person, including the subject of an investigation.
When ZPICs make the determination of potential fraud waste or abuse, the ZPICs shall coordinate with the OIG and, as appropriate, refer the case to the OIG. When the ZPIC makes the determination that a situation is not potential fraud, the ZPIC shall refer these situations to the appropriate unit at the MAC.
4.2.1 - Examples of Medicare Fraud
This section applies to ZPICs and MACs.
The most frequent kind of fraud arises from a false statement or misrepresentation made, or caused to be made, that is material to entitlement or payment under the Medicare program. The violator may be a provider/supplier, a beneficiary, an employee of a provider/supplier, or some other person or business entity, including a billing service or a contractor employee.
Providers/suppliers have an obligation, under law, to conform to the requirements of the Medicare program. Fraud committed against the program may be prosecuted under various provisions of the United States Code and could result in the imposition of restitution, fines, and, in some instances, imprisonment. In addition, a range of administrative sanctions (such as exclusion from participation in the program) and civil monetary penalties may be imposed when facts and circumstances warrant such action.
Fraud may take such forms as (this is not an exhaustive list):
· Incorrect reporting of diagnoses or procedures to maximize payments.
· Billing for services not furnished and/or supplies not provided. This includes billing Medicare for appointments that the patient failed to keep.
· Billing that appears to be a deliberate application for duplicate payment for the same services or supplies, billing both Medicare and the beneficiary for the same service, or billing both Medicare and another insurer in an attempt to get paid twice.
· Altering claim forms, electronic claim records, medical documentation, etc., to obtain a higher payment amount.
· Soliciting, offering, or receiving a kickback, bribe, or rebate (e.g., paying for a referral of patients in exchange for the ordering of diagnostic tests and other services or medical equipment).
· Unbundling or “exploding” charges.
· Completing Certificates of Medical Necessity for patients not personally and professionally known by the provider.
· Participating in schemes that involve collusion between a provider and a beneficiary, or between a supplier and a provider, that result in higher costs or charges to the Medicare program.
· Participating in schemes that involve collusion between a provider and a MAC employee where the claim is assigned (e.g., the provider deliberately overbills for services, and the MAC employee then generates adjustments with little or no awareness on the part of the beneficiary).
· Billing based on “gang visits,” (e.g., a physician visits a nursing home and bills for 20 nursing home visits without furnishing any specific service to individual patients).
· Misrepresenting dates and descriptions of services furnished or the identity of the beneficiary or the individual who furnished the services.
· Billing noncovered or nonchargeable services as covered items.
· Repeatedly violating the participation agreement, assignment agreement, or the limitation amount.
· Using another person's Medicare card to obtain medical care.
· Giving false information about provider ownership.
· Using the adjustment payment process to generate fraudulent payments.
Examples of cost report fraud include (this is not an exhaustive list):
· Incorrectly apportioning costs on cost reports.
· Including costs of noncovered services, supplies, or equipment in allowable costs.
· Providers making arrangements with employees, independent contractors, suppliers, and others that appear to be designed primarily to overcharge the program through various devices (commissions, fee splitting) to siphon off or conceal illegal profits.
· Billing Medicare for costs that were not incurred or were attributable to nonprogram activities, other enterprises, or personal expenses.
· Repeatedly including unallowable cost items on a provider's cost report for purposes of establishing a basis for appeal.
· Manipulating statistics to obtain additional payment, such as increasing the square footage in the outpatient areas to maximize payment.
· Claiming bad debts without first genuinely attempting to collect payment.
· Making improper payments to physicians for certain hospital-based physician arrangements.
· Paying amounts to owners or administrators that have been determined to be excessive in prior cost report settlements.
· Reporting days improperly that result in an overpayment if not adjusted.
· Depreciating assets that have been fully depreciated or sold.
· Using depreciation methods not approved by Medicare.
· Repaying interest expense for loans that were for an offset of interest income against the interest expense.
· Reporting program data where provider program amounts cannot be supported.
· Allocating costs improperly related to organizations that have been determined to be improper.
· Manipulating accounting.
4.2.2 - Zone Program Integrity Contractor (Rev.)
This section applies to ZPICs.
The ZPIC is responsible for preventing, detecting, and deterring fraud, waste, and abuse in Medicare and Medicaid through the collaboration of the Medicare-Medicaid Data Match Program (Medi-Medi). The ZPIC:
· Prevents fraud by identifying program vulnerabilities.
· Proactively identifies incidents of potential fraud, waste, and abuse that exist within its service area and takes appropriate action on each case.
· Investigates (determines the factual basis of) allegations of fraud made by beneficiaries, providers/suppliers, the Centers for Medicare & Medicaid Services (CMS), the Office of the Inspector General (OIG), and other sources.
· Explores all available sources of fraud leads in its zone, including the State Medicaid agency and the Medicaid Fraud Control Unit (MFCU).
· Initiates appropriate administrative actions where there is reliable evidence of fraud, including but not limited to payment suspension and revocation.
· Refers cases to the OIG/Office of Investigations (OIG/OI) for consideration of civil and criminal prosecution and/or application of administrative sanctions (§4.18 and chapter 8,).
· Refers any necessary provider/supplier and beneficiary outreach to the provider outreach and education (POE) staff at the Medicare Administrative Contractor (MAC).
· Initiates and maintains networking and outreach activities to ensure effective interaction and exchange of information with internal components as well as outside groups.
· Partners with State Medicaid Program Integrity units to perform the above activities for the Medi-Medi program.
· Works closely with CMS on joint projects, investigations and other proactive, anti-fraud activities.
ZPICs are required to use a variety of techniques, both proactive and reactive, to address any potentially fraudulent, wasteful, or abusive billing practices based on the various leads they receive.
Proactive leads are leads identified or self-initiated by the ZPIC. Examples of proactive leads include, but are not limited to, ZPIC data analysis that uncovers inexplicable aberrancies which indicate potentially fraudulent, wasteful or abusive billing for specific providers/suppliers, the discovery of a new lead by a ZPIC during a provider/supplier or beneficiary interview, and the combining of information from a variety of sources to create a new lead. ZPICs shall pursue leads identified through data analysis (ZPICs shall follow PIM chapter 2, §2.3 for sources of data), the Internet, the Fraud Investigation Database (FID), news media, etc. For workload reporting purposes, the ZPICs shall only identify as proactive those investigations and cases that the ZPICs self-initiated.
ZPICs shall take prompt action after scrutinizing billing practices, patterns, or trends that may indicate fraudulent billing, (i.e., reviewing data for inexplicable aberrancies and relating the aberrancies to specific providers/suppliers, identifying “hit and run” providers/suppliers, etc.).
Fraud leads from any external source (e.g., law enforcement, CMS referrals, beneficiary complaints, and the Fraud Prevention System) are considered to be reactive and not proactive. However, taking ideas from external sources, such as Fraud Alerts, and using them to look for unidentified aberrancies within ZPIC data is proactive.
4.2.2.1 - Organizational Requirements (Rev.)
This section applies to ZPICs and MACs, as indicated.
ZPIC PI managers shall have sufficient authority to guide program integrity (PI) activities and establish, control, evaluate, and revise fraud-detection procedures to ensure their compliance with Medicare requirements.
ZPIC PI managers shall prioritize work coming into the ZPIC to ensure that investigations with the greatest program impact and/or urgency are given the highest priority. ZPICs shall prioritize all work on an ongoing basis as new work is received. The ZPICs shall follow the PIM Chapter 16 for Fraud Prevention System (FPS) requirements and prioritization. The ZPIC shall prioritize the top 100 ASRs in the FPS along with other investigation work based on the PIM prioritization requirements in §4.2.2.1. The ZPIC shall contact its Contracting Officer’s Representative (COR) and Investigations and Audits Group (IAG) Business Function Lead (BFL) if it has any questions or concerns about prioritization of workload.
Note: The UPIC shall follow the FPS requirements in its SOW for prioritizing leads provided by CMS, including FPS.
Allegations having the greatest program impact would include investigations cases involving:
· Patient abuse or harm
· Multi-state fraud
· High dollar amounts of potential overpayment
· Likelihood of an increase in the amount of fraud or enlargement of a pattern
· Law enforcement requests for assistance that involve responding to court-imposed deadlines
· Law enforcement requests for assistance in ongoing investigations that involve national interagency (Department of Health and Human Services [HHS]-Department of Justice [DOJ]) initiatives or projects.
Note: ZPICs and MACs shall give high priority to fraud, waste, or abuse complaints made by Medicare supplemental insurers. If a referral by a Medigap insurer includes investigatory findings indicating fraud stemming from site reviews, beneficiary interviews, and/or medical record reviews, ZPICs shall 1) conduct an immediate data run to determine possible Medicare losses, and 2) refer the case to the OIG.
4.2.2.2 - Liability of Zone Program Integrity Contractor - Employees
This section applies to ZPICs.
Under the terms of their contracts (refer to the Code of Federal Regulations (CFR) 42 CFR §421.316(a)), ZPICs, their employees, and professional consultants are protected from criminal or civil liability as a result of the activities they perform under their contracts as long as they use due care. If a ZPIC or any of its employees or consultants are named as defendants in a lawsuit, CMS will determine, on a case-by-case basis, whether to request that the U.S. Attorney’s office offer legal representation. If the U.S. Attorney’s office does not provide legal representation, the ZPIC will be reimbursed for the reasonable cost of legal expenses it incurs in connection with defense of the lawsuit, as long as funds are available and the expenses are otherwise allowable under the terms of the contract.
If a ZPIC is served with a complaint, the ZPIC shall immediately contact its chief legal counsel and the Contracting Officer’s Representative (COR). The ZPIC shall forward the complaint to the HHS Office of the Regional Chief Counsel (the CMS regional attorney) who, in turn, will notify the U.S. Attorney’s office. The HHS Office of the Regional Chief Counsel and/or the COR will notify the ZPIC whether legal representation will be sought from the U.S. Attorney’s office prior to the deadline for filing an answer to the complaint.
4.2.2.3 – Anti-Fraud Training
This section applies to ZPICs.
All levels of ZPIC employees shall know the goals and techniques of fraud detection and control in general, and as they relate to their own areas of responsibility and the level of knowledge required (i.e., general orientation for new employees and highly technical sessions for existing staff). All ZPIC staff shall be adequately qualified for the work of detecting and investigating situations of potential fraud, waste, or abuse.
4.2.2.3.1 - Training for Law Enforcement Organizations
The FBI agents, OIG, and DOJ attorneys need to understand Medicare. ZPICs shall conduct special training programs for them upon request. ZPICs should also consider inviting appropriate DOJ, OIG, and FBI personnel to existing programs for orienting employees about ZPIC operations or provide the aforementioned personnel with briefings on specific cases or Medicare issues.
4.2.2.4 - Procedural Requirements
This section applies to ZPICs and MACs, as indicated.
The MAC personnel conducting each segment of claims adjudication, medical review (MR), and professional relations functions shall be aware of their responsibility for identifying potential fraud, waste, or abuse and be familiar with internal procedures for forwarding potential fraud, waste, or abuse instances to the ZPIC. Any area within the MAC (e.g., MR, enrollment, second-level screening staff) that refers potential fraud and abuse to the ZPIC shall maintain a log of all these referrals. At a minimum, the log shall include the following information: provider/physician/supplier name, beneficiary name, Health Insurance Claim Number (HICN), nature of the referral, date the referral is forwarded to the ZPIC, name and contact information of the individual who made the referral, and the name of the ZPIC to whom the referral was made.
The MACs shall provide written procedures for personnel in various contractor functions (claims processing, MR, beneficiary services, provider/supplier outreach and education (POE), cost report audit, etc.) to help identify potential fraud situations. The MACs shall include provisions to ensure that personnel shall:
· Refer potential fraud, waste, or abuse situations promptly to the ZPIC.
· Forward complaints alleging fraud through the second-level screening staff to the ZPIC.
· Maintain confidentiality of referrals to the ZPIC.
· Forward to the ZPIC detailed documentation of telephone or personal contacts involving fraud issues discussed with providers/suppliers or provider/supplier staff, and retain such information in individual provider/supplier files.
ZPICs shall ensure the performance of the functions below and have written procedures for implementing these functions:
Investigations
· Keep educational/warning correspondence with providers/suppliers and other fraud documentation concerning specific issues in individual provider/supplier files so that ZPICs are able to retrieve such documentation easily.
· Maintain documentation on the number of investigations alleging fraud, waste or abuse, the number of cases referred to the OIG/OI (and the disposition of those cases), processing time of investigations, and types of violations referred to the OIG (e.g., item or service not received, unbundling, waiver of co-payment).
· Conduct investigations (including procedures for reviewing questionable billing codes) and make the appropriate beneficiary and provider contacts.
Communications/Coordination
· Maintain communication and information flowing between the ZPIC and the MAC MR staff, and as appropriate, MAC audit staffs.
· Communicate with the MAC MR staff on all findings of overutilization and coordinate with the MAC POE staff to determine what, if any, education has been provided before any PI investigation is pursued.
· Obtain and share information on health care fraud issues/fraud investigations among MACs, ZPICs, CMS, and law enforcement.
· Coordinate and attend fraud-related meetings/conferences and inform and include all appropriate parties about these meetings/conferences. These meetings/conferences include, but are not limited to, health care task force meetings and conference calls.
· Distribute Fraud Alerts released by CMS to the appropriate parties. Share ZPIC findings on Fraud Alerts with CMS and all ZPICs either nationally or within the appropriate zone.
· Serve as a resource to CMS, as necessary. For example, serve as a resource to CMS on the FID.
· Take appropriate administrative action on investigations prior to referral to OIG, and on cases not accepted or returned by the OIG or other investigative agencies. At a minimum, provide information for recovery of identified overpayments and other corrective actions discussed in PIM chapter 8.
· Report to the COR and IAG BFL all situations that have been identified where a provider consistently fails to comply with the provisions of the assignment agreement.
· Coordinate and communicate with the MR units within the MACs to avoid duplication of work.
Law Enforcement
· Serve as a reference point for law enforcement and other organizations and agencies to contact when they need help or information on Medicare fraud issues and do not know whom to contact.
· Hire and retain employees who are qualified to testify in a criminal and civil trial when requested by law enforcement.
· Provide support to law enforcement agencies for investigation of potential fraud, including those for which an initial referral to law enforcement did not originate from the ZPIC.
· Meet (in person or via telephone call) with the OIG agents to discuss pending or potential cases, as necessary.
· Meet (in person or via telephone) when needed with the DOJ to enhance coordination on current or pending cases.
· Furnish all available information upon request to the OIG/OI with respect to excluded providers/suppliers requesting reinstatement.
Notify via e-mail the COR and IAG BFL who will obtain approval or disapproval when the ZPIC is asked to accompany the OIG/OI or any other law enforcement agency onsite to a provider/supplier for the purpose of gathering evidence in potential fraud case (e.g., executing a search warrant). However, law enforcement must make clear the role of ZPIC personnel in the proposed onsite visit. The potential harm to the case and the safety of ZPIC personnel shall be thoroughly evaluated. The ZPIC personnel shall properly identify themselves as ZPIC employees, and under no circumstances shall they represent themselves as law enforcement personnel or special agents. Lastly, under no circumstances shall ZPIC personnel accompany law enforcement in situations where their personal safety is in question.
Training
· Work with the COR and IAG BFL to develop and organize external programs and perform training, as appropriate, for law enforcement, ombudsmen, grantees (e.g., Senior Medicare Patrols), and other CMS health care partners (e.g., Administration on Aging (AoA), State MFCUs).
· Help to develop fraud-related outreach materials (e.g., pamphlets, brochures, videos) in cooperation with beneficiary services and/or provider relations departments of the MACs for use in their training. Submit written outreach material to the COR and IAG BFL for clearance.
Assist in preparing and developing fraud-related articles for MAC newsletters/bulletins. The ZPIC shall submit such materials to the CORs with a copy to the IAG BFLs via the following email address, CPIFraudRelatedLeads@cms.hhs.gov.
· Provide resources and training for the development of existing employees and new hires.
The MACs shall ensure the performance of the functions below and have written procedures for these functions:
· Ensure no payments are made for items or services ordered, referred, or furnished by an individual or entity following the effective date of exclusion (refer to PIM chapter 8, for exceptions).
· Ensure all instances where an excluded individual or entity that submits claims for which payment may not be made after the effective date of the exclusion are reported to the OIG (refer to PIM chapter 8,).
· Ensure no payments are made for an excluded individual or entity who is employed by a Medicare provider or supplier.
4.2.2.4.1 - Maintain Controlled Filing System and Documentation (Rev.)
The ZPICs shall maintain files on providers/suppliers who have been the subject of complaints, prepayment flagging, ZPIC investigations, OIG/OI and/or DOJ investigations, U.S. Attorney prosecution, and any other civil, criminal, or administrative action for violations of the Medicare or Medicaid programs. The files shall contain documented warnings and educational contacts, the results of previous investigations, and copies of complaints resulting in investigations.
The ZPICs shall set up a system for assigning and controlling numbers at the initiation of investigations, and shall ensure that:
• All incoming correspondence or other documentation associated with an investigation contains the same file number and is placed in a folder containing the original investigation material.
• Investigation files are adequately documented to provide an accurate and complete picture of the investigative effort.
• All contacts are clearly and appropriately documented.
• Each file contains the initial prioritization assigned and all updates.
• Each investigation file lists the name, organization, address, and telephone numbers of all persons with whom ZPIC can discuss the investigation (including those working within the ZPIC).
It is important to establish and maintain histories and documentation on all fraud and abuse investigations and cases. ZPICs shall conduct periodic reviews of data over the past several months to identify any patterns of potential fraud, waste, or abusive billings for particular providers. The ZPICs shall ensure that all evidentiary documents are kept free of annotations, underlining, bracketing, or other emphasizing pencil, pen, or similar marks.
The ZPIC shall establish an internal monitoring and investigation review system to ensure the adequacy and timeliness of fraud and abuse activities.
4.2.2.4.2 - File/Document Retention (Rev. 71, 04-09-04)
Files/documents shall be retained for 10 years. However, files/documents shall be retained indefinitely and shall not be destroyed if they relate to a current investigation or litigation/negotiation; ongoing Workers’ Compensation set aside arrangements, or documents which prompt suspicions of fraud and abuse of overutilization of services. This will satisfy evidentiary needs and discovery obligations critical to the agency’s litigation interests.
4.2.2.5 – Reserved for Future Use (Rev. 101, Issued: 01-28-05, Effective: 02-28-05, Implementation: 02-28-05)
4.2.2.5.1 – Reserved for Future Use (Rev. 101, Issued: 01-28-05, Effective: 02-28-05, Implementation: 02-28-05)
4.2.2.5.2 – Reserved for Future Use
4.2.2.6 – Program Integrity Security Requirements
This section applies to ZPICs.
To ensure a high level of security for the ZPIC functions, the ZPICs shall develop, implement, operate, and maintain security policies and procedures that meet and conform to the requirements of the Business Partners System Security Manual (BPSSM) and the CMS Informational Security Acceptable Risk Safeguards (ARS). Further, the ZPICs shall adequately inform and train all ZPIC employees to follow ZPIC security policies and procedures so that the information the ZPICs obtain is confidential.
Note: The data ZPICs collect in administering ZPIC contracts belong to CMS. Thus, ZPICs collect and use individually identifiable information on behalf of the Medicare program to routinely perform the business functions necessary for administering the Medicare program, such as MR and program integrity activities to prevent fraud and abuse. Consequently, any disclosure of individually identifiable information without prior consent from the individual to whom the information pertains, or without statutory or contract authority, requires CMS’ prior approval.
This section discusses broad security requirements that ZPICs shall follow. The requirements listed below are in the BPSSM or ARS. There are several exceptions. The first is requirement A (concerning ZPIC operations), which addresses several broad requirements; CMS has included requirement A here for emphasis and clarification. Two others are in requirement B (concerning sensitive information) and requirement G (concerning telephone security). Requirements B and G relate to security issues that are not systems related and are not in the BPSSM.
A. Zone Program Integrity Contractor Operations
· The ZPICs shall conduct their activities in areas not accessible to the general public.
· The ZPICs shall completely segregate themselves from all other operations. Segregation shall include floor-to-ceiling walls and/or other measures described in ARS Appendix B PE-3 and CMS-2 that prevent unauthorized persons access to or inadvertent observation of sensitive and investigative information.
· Other requirements regarding ZPIC operations shall include §§3.1, 3.1.2, 3.10.2, 4.1.1.2, 4.2, 4.2.5, and 4.2.6 of the BPSSM.
B. Handling and Physical Security of Sensitive and Investigative Material Refer to ARS Appendix B PE-3 and CMS-1 for definitions of sensitive and investigative material.
In addition, ZPICs shall follow the requirements provided below:
· Establish a policy that employees shall discuss specific allegations of fraud only within the context of their professional duties and only with those who have a valid need to know, which includes (this is not an exhaustive list):
Appropriate CMS personnel;
ZPIC staff;
MAC MR staff;
ZPIC or MAC audit staff;
ZPIC or MAC data analysis staff;
ZPIC or MAC senior management; or ZPIC or MAC corporate counsel.
· The ASRs require that:
The following workstation security requirements are specified and implemented: (1) what workstation functions can be performed, (2) the manner in which those functions are to be performed, and (3) the physical attributes of the surroundings of a specific workstation or class of workstation that can access sensitive CMS information. CMS requires that for ZPICs all local workstations as well as workstations used at home by ZPICs comply with these requirements.
If ZPIC employees are authorized to work at home on sensitive data, they shall observe the same security practices that they observe at the office. These shall address such items as viruses, virtual private networks, and protection of sensitive data, including printed documents.
Users are prohibited from installing desktop modems.
The connection of portable computing or portable network devices on the CMS claims processing network is restricted to approved devices only. Removable hard drives and/or a Federal Information Processing Standards (FIPS)-approved method of cryptography shall be employed to protect information residing on portable and mobile information systems.
Alternate work sites are those areas where employees, subcontractors, consultants, auditors, etc. perform work associated duties. The most common alternate work site is an employee’s home. However, there may be other alternate work sites such as training centers, specialized work areas, processing centers, etc. For alternate work site equipment controls, (1) only CMS Business Partner-owned computers and software are used to process, access, and store sensitive information; (2) a specific room or area that has the appropriate space and facilities is used; (3) means are available to facilitate communication with the managers or other members of the Business Partner Security staff in case of security problems; (4) locking file cabinets or desk drawers; (5) “locking hardware” to secure IT equipment to larger objects such as desks or tables; and (6) smaller Business Partner-owned equipment is locked in a storage cabinet or desk when not in use. If wireless networks are used at alternate work sites, wireless base stations are placed away from outside walls to minimize transmission of data outside of the building.
The ZPIC shall also adhere to the following:
· Ensure the mailroom, general correspondence, and telephone inquiries procedures maintain confidentiality whenever the ZPIC receives correspondence, telephone calls, or other communication alleging fraud. Further, all internal written operating procedures shall clearly state security procedures.
· Direct mailroom staff not to open ZPIC mail in the mailroom unless the ZPIC has requested the mailroom do so for safety and health precautions. Alternately, if mailroom staff opens ZPIC mail, mailroom staff shall not read the contents.
· For mail processing sites separate from the ZPICs, the ZPICs shall minimize the handling of ZPIC mail by multiple parties before delivery to the ZPIC.
· The ZPICs shall mark mail to the CMS Central Office or to another ZPIC “personal and confidential” and address it to a specific person.
· Where more specialized instructions do not prohibit ZPIC employees, they may retain sensitive and investigative materials at their desks, in office work baskets, and at other points in the office during the course of the normal work day. Regardless of other requirements, the employees shall restrict access to sensitive and investigative materials, and ZPIC staff shall not leave such material unattended.
· The ZPIC staff shall safeguard all sensitive or investigative material when the materials are being transported or sent by ZPIC staff.
· The ZPICs shall maintain a controlled filing system (refer to PIM chapter 20, §20.1.1.2).
C. Designation of a Security Officer The security officer shall take such action as is necessary to correct breaches of the security standards and to prevent recurrence of the breaches. In addition, the security officer shall document the action taken and maintain that documentation for at least seven (7) years. Actions shall include:
· Within one (1) hour of discovering a security incident, clearly and accurately report the incident following BPSSM requirements for reporting of security incidents. For purposes of this requirement, a security incident is the same as the definition in §3.6 of the BPSSM, Incident Reporting and Response.
· Specifically, the report shall address the following where appropriate:
Types of information about beneficiaries shall at a minimum address whether the compromised information includes name, address, Health Insurance Claim Numbers (HICNs), and date of birth;
Types of information about providers/suppliers shall at a minimum address if the compromised information includes name, address, and provider/supplier ID;
Whether law enforcement is investigating any of the providers/suppliers with compromised information; and Police reports.
· Provide additional information that CMS requests within 72 hours of the request.
· If CMS requests, issue a Fraud Alert to all CMS Medicare contractors within 72 hours of the discovery that the data was compromised, listing the HICNs and provider/supplier IDs that were compromised.
· Within 72 hours of discovery of a security incident, when feasible, review all security measures and revise them if necessary so they are adequate to protect data against physical or electronic theft.
Refer to §3.1 of the BPSSM and Attachment 1 of this manual section (letter from Director, Office of Financial Management, concerning security and confidentiality of ZPIC data) for additional requirements.
D. Staffing of the Zone Program Integrity Contractor and Security Training
The ZPIC shall perform thorough background and character reference checks, including at a minimum credit checks, for potential employees to verify their suitability for employment. Specifically, background checks shall at least be at level 2- moderate risk. (People with access to sensitive data at CMS have a level 5 risk). The ZPIC may require investigations above a level 2 if the ZPIC believes the higher level is required to protect sensitive information.
At the point the ZPIC makes a hiring decision for a ZPIC position, and prior to the selected person’s starting work, the ZPIC shall require the proposed candidate to fill out a conflict of interest declaration, as well as a confidentiality statement.
Annually, the ZPICs shall require existing employees to complete a conflict of interest declaration, as well as a confidentiality statement.
The ZPICs shall not employ temporary employees, such as those from temporary agencies, or students (nonpaid or interns).
At least once a year, the ZPICs shall thoroughly explain to and discuss with employees the special security considerations under which the ZPIC operates. Further, this training shall emphasize that in no instance shall employees disclose sensitive or investigative information, even in casual conversation. The ZPIC shall ensure that employees understand the training provided.
Refer to §2.0 of the BPSSM and ARS Appendix B AT-2, AT-3, AT-4, SA-6, MA-5.0, PE-5.CMS.1, IR2-2.2, CP 3.1, CP 3.2, CP 3.3, and SA 3.CMS.1 for additional training requirements.
E. Access to Zone Program Integrity Contractor Information Refer to §2.3.4 of the BPSSM for requirements regarding access to ZPIC information.
The ZPIC shall notify the OIG if parties without a need to know are asking inappropriate questions regarding any investigations. The ZPICs shall refer all requests from the press related to the Medicare Integrity Program to the CMS contracting officer with a copy to the Primary COR and Alternate COR for approval prior to release. This includes, but is not limited to, contractor initiated press releases, media questions, media interviews, and Internet postings.
F. Computer Security Refer to §4.1.1 of the BPSSM for the computer security requirements.
G. Telephone and Fax Security
The ZPICs shall implement phone security practices. The ZPICs shall discuss investigations only with those individuals who need to know the information and shall not divulge information to individuals not known to the ZPIC involved in the investigation of the related issue.
Additionally, the ZPICs shall only use CMS, the OIG, the DOJ, and the FBI phone numbers that they can verify. To assist with this requirement, ZPIC management shall provide ZPIC staff with a list of the names and telephone numbers of the individuals of the authorized agencies that the ZPICs deal with and shall ensure that this list is properly maintained and periodically updated.
Employees shall be polite and brief in responding to phone calls but shall not volunteer any information or confirm or deny that an investigation is in process. However, ZPICs shall not respond to questions concerning any case the OIG, the FBI, or any other law enforcement agency is investigating. The ZPICs shall refer such questions to the OIG, the FBI, etc., as appropriate.
Finally, the ZPICs shall transmit sensitive and investigative information via facsimile (fax) lines only after the ZPIC has verified that the receiving fax machine is secure. Unless the fax machine is secure, ZPICs shall make arrangements with the addressee to have someone waiting at the receiving machine while the fax is transmitting. The ZPICs shall not transmit sensitive and investigative information via fax if the sender must delay a feature, such as entering the information into the machine’s memory.
4.3 – Medical Review for Program Integrity Purposes (Rev.)
This section applies to ZPICs and MACs, as indicated.
As stated in PIM chapter 1, §1.1, CMS’ national objectives and goals as they relate to medical review (MR) are as follows:
Increase the effectiveness of medical review payment safeguard activities;
Exercise accurate and defensible decision-making on medical review of claims;
Place emphasis on reducing the paid claims error rate by notifying the individual billing entities (i.e., providers, suppliers, or other approved clinicians) of medical review findings and making appropriate referrals to provider outreach and education (POE); and Collaborate with other internal components and external entities to ensure correct claims payment and to address situations of potential fraud, waste, or abuse.
The statutory authority for the MR program includes Sections 1812, 1816, 1832, 1833(e), 1842, 1842(a)(2)(B), 1861, 1862(a), 1862(a)(1), 1861, and 1874 of the Social Security Act (the Act). In addition, the regulatory authority for the MR program rests in 42 CFR 421.100 for intermediaries and 42 CFR 421.200 for carriers. Refer to PIM, chapter 3, for detailed information about the statutory and regulatory authorities.
Data analysis is an essential first step in determining whether patterns of claims submission and payment indicate potential problems. Such data analysis may include simple identification of aberrancies in billing patterns within a homogeneous group, or much more sophisticated detection of patterns within claims or groups of claims that might suggest improper billing or payment. The ZPIC’s ability to make use of available data and apply innovative analytical methodologies is critical to the success of MR for PI purposes. Refer to PIM chapter 2, in its entirety for MR and PI data analysis requirements.
The ZPIC and the MAC MR units shall have ongoing discussions and close working relationships regarding situations identified that may be signs of potential fraud, waste, or abuse. MACs shall also include the cost report audit unit in the on-going discussions. MAC MR staff shall coordinate and communicate with their associated ZPICs to ensure coordination of efforts, to prevent inappropriate duplication of review activities, and to assure contacts made by the MAC are not in conflict with program integrity related activities, as defined by the Joint Operating Agreement (JOA).
A. Referrals from the Medicare Administrative Contractor to the Zone Program Integrity Contractor If a provider/supplier appears to have knowingly and intentionally furnished services that are not covered, or filed claims for services not furnished as billed, or made any false statement on the claim or supporting documentation to receive payment, the MAC MR unit personnel shall discuss this matter with the ZPIC. If the ZPIC agrees that there is potential fraud, the MAC MR unit shall then make a referral to the ZPIC for investigation.
Provider/supplier documentation that shows a pattern of repeated misconduct or conduct that is clearly abusive or potentially fraudulent, despite provider/supplier education and direct contact with the provider/supplier to explain identified errors, shall be referred to the ZPIC.
The focus of MAC MR is to reduce the error rate through medical review and provider/supplier notification and feedback, whereas ZPIC MR for PI focuses on addressing situations of potential fraud, waste, and abuse.
B. Referrals from the Zone Program Integrity Contractor to the Medical Review Unit and Other Units The ZPICs are also responsible for preventing and minimizing the opportunity for fraud. The ZPICs shall identify procedures that may make Medicare vulnerable to questionable billing or improper practices and take appropriate action.
CMS has implemented recurring edit modules in all claims processing systems to allow ZPICs…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .