top of page

The New CMS Enforcement Model You Haven’t Heard About Yet

  • Writer: Jessica Zeff
    Jessica Zeff
  • Aug 6
  • 3 min read

At first glance, the proposed 2027 Home Health Prospective Payment System rule appears to be a routine update. But buried within the proposed rule is something far more significant. CMS is proposing to expand its authority to deny or revoke Medicare enrollment based on fraud risk, ownership concerns, and other program integrity factors before improper claims are ever submitted.


In fact, CMS has already begun implementing this philosophy across the Medicare and Medicaid programs. This proposed rule simply articulates what has become an increasingly clear enforcement strategy: stop fraud before it enters the system rather than recover taxpayer dollars after they've been paid.


The Pattern Has Been There All Along


Over the past year, federal healthcare agencies have taken a series of actions that, on their own, appeared unrelated. CMS has imposed enrollment moratoria in areas experiencing significant fraud risk. High-risk provider and supplier enrollments—including certain DMEPOS suppliers—have received heightened scrutiny and, in some cases, enrollment restrictions where existing authorities permitted. HHS has also delayed substantial Medicaid payments while requesting additional documentation to support claims that raised program integrity concerns (think California and Minnesota).


More recently, the Department of Justice announced its largest healthcare fraud takedown in history, highlighting the role of the federal Data Fusion Center and sophisticated data analytics in identifying fraudulent billing patterns before they became even more widespread.


Individually, each announcement reflected a different program or enforcement tool. Collectively, they tell a much larger story. Federal healthcare enforcement is no longer centered on finding fraud after claims have been paid. It is increasingly focused on preventing questionable providers, claims, and payments from entering the system in the first place.


The End of "Pay and Chase"


For decades, Medicare largely operated under what compliance professionals have come to know as a "pay and chase" model. Providers enrolled. Claims were paid. Months—or sometimes years—later, auditors, contractors, or prosecutors identified improper billing and sought repayment through audits, investigations, False Claims Act litigation, or criminal prosecution.


That approach recovered billions of dollars. It also meant that fraudulent providers often collected millions before enforcement ever caught up with them.


The proposed rule reflects a different philosophy. Rather than relying primarily on retrospective enforcement, CMS is seeking broader authority to evaluate risk before providers enter or continue participating in the Medicare program. Ownership structures, prior conduct, enrollment history, and other indicators of fraud risk become increasingly important long before the first claim is submitted.


This is preventive regulation rather than retrospective enforcement.


Why This Matters to Every Healthcare Organization


Although these proposals appear in a home health payment rule, the underlying philosophy extends far beyond one provider type. Compliance has traditionally focused on billing accuracy, documentation, coding, and responding to audits. Those responsibilities remain essential.


But organizations should recognize that regulators are now placing increasing emphasis on questions that arise much earlier in the compliance lifecycle.


  • Who owns the organization?

  • How transparent is its governance?

  • Do enrollment applications accurately reflect ownership and control?

  • Are business relationships structured appropriately?

  • Do leaders demonstrate the kind of governance that gives regulators confidence the organization belongs in the Medicare program?


These are no longer merely administrative questions. They have become program integrity questions.


Compliance Is Moving Upstream


The implications for compliance officers are significant. An effective compliance program can no longer focus exclusively on preventing billing errors after operations begin. Increasingly, compliance has to influence decisions before the organization bills its first Medicare claim or before regulators decide whether the organization should continue participating at all.


Enrollment integrity. Governance. Ownership transparency. Leadership accountability. Risk assessment. These areas are becoming just as important as coding audits and repayment analyses.


The Bigger Picture


The proposed rule should not be viewed as an isolated policy change. Instead, it represents another step in a broader transformation of federal healthcare oversight.

Whether through advanced analytics, multi-agency fraud investigations, enrollment moratoria, payment suspensions, or expanded screening authority, CMS and its federal partners are steadily shifting healthcare enforcement upstream.


The goal is no longer simply to identify fraud. It is to prevent fraud from entering the healthcare system at all.


For healthcare organizations, that represents a fundamental shift in regulatory expectations.


And for compliance professionals, it reinforces an important reality: the future of compliance will be defined not only by how well organizations respond to audits, but by how effectively they demonstrate, before regulators ever ask, that they deserve the privilege of participating in federal healthcare programs.

 

Sources:

Comments


bottom of page