The CMS Fraud Proposal That Reaches Further Than You'd Expect
- Jessica Zeff

- 11 minutes ago
- 4 min read

If you've never heard of CRUSH, you're probably not alone. CRUSH stands for Comprehensive Regulations to Uncover Suspicious Healthcare, and while there isn't a CRUSH regulation to comply with yet, it is something healthcare organizations should probably have on their radar.
In February 2026, CMS issued a Request for Information (RFI) asking for stakeholder input on potential changes to the way it prevents and responds to fraud, waste and abuse. The comment period closed March 30, and a proposed CRUSH rule is currently scheduled for October 2026.
What makes CRUSH particularly interesting is the breadth of who and what it could impact. This isn't just about DME fraud. The ideas CMS is considering potentially touch hospitals, laboratories, Medicare Advantage and Part D plans, Medicaid and CHIP, DMEPOS suppliers, provider enrollment, billing, AI, payment suspensions, ownership disclosure, beneficiary solicitation and more.
And there is an important tension running through many of the proposals: How do you give CMS stronger tools to stop genuine fraud quickly without creating unnecessary administrative burdens, payment disruptions and due-process problems for legitimate providers? That balance may ultimately be one of the most important things to watch as CRUSH develops.
So, what exactly is CMS considering?
A broader program integrity toolbox
At its core, CRUSH appears to be about giving CMS more tools and potentially more flexibility to intervene when it identifies suspicious activity.
CMS asked whether it should strengthen or modify its approaches to provider enrollment and revocation, medical review, audits and investigations, payment suspensions, claims analytics and other program integrity activities.
It also asked about expanding payment suspension authority in Medicare Advantage and Part D, including whether plans should be required to suspend payments when directed by CMS.
That's significant. It reflects a broader shift we've been seeing in federal program integrity: trying to identify and stop suspicious payments before the money goes out the door, rather than relying on traditional "pay and chase" enforcement after the fact.
Provider enrollment and ownership could get more scrutiny
One of the more interesting proposals involves identity verification and ownership.
CMS is concerned about fraud involving opaque ownership structures and individuals operating outside the United States. Among other things, it asked about enhanced identity proofing, expanding fingerprinting and criminal background checks, and even whether individuals with a 5% or greater ownership or control interest in a Medicare provider or supplier should be required to be U.S. citizens or lawful permanent residents.
There are obvious fraud-prevention benefits to knowing who actually owns and controls an organization.
There are also obvious complications for legitimate healthcare organizations with international investors, foreign parent companies or cross-border ownership structures.
Medicare Advantage is very much part of the conversation
CRUSH also highlights a potential gap between Traditional Medicare and Medicare Advantage.
CMS is concerned that providers or suppliers whose Traditional Medicare enrollment has been revoked may, in some circumstances, continue billing Medicare Advantage plans.
One option CMS floated is requiring providers and suppliers to enroll in Traditional Medicare as a condition of billing Medicare Advantage, or perhaps applying that requirement only to higher-risk provider and supplier types.
For organizations operating primarily or exclusively in Medicare Advantage, that's an issue worth watching closely.
Certain sectors are getting particular attention
The RFI also identifies some specific areas CMS considers higher risk.
DMEPOS: CMS is considering additional safeguards for non-participating DMEPOS suppliers billing Medicare Advantage, including whether they should meet accreditation and enrollment requirements similar to Traditional Medicare.
Laboratories: Genetic and molecular diagnostic testing receives considerable attention. CMS is exploring whether additional safeguards could reduce fraud.
High-risk claims: CMS even asked about shortening Medicare's claims filing deadline from one year to somewhere between 90 and 180 days for certain high-risk items, services, providers or suppliers.
That last proposal illustrates the trade-off running through CRUSH. A shorter billing window could make it harder to stockpile and later submit fraudulent claims but it could also create real operational challenges for legitimate providers trying to resolve documentation, coverage or billing issues.
And then there's AI
One part of the RFI that caught my attention is CMS's interest in AI.
CMS specifically asked about the use of AI in Medicare Advantage coding oversight and hospital billing, including whether AI can improve coding accuracy and efficiency and assist compliance oversight.
But CMS is also asking about the risks: inaccurate coding recommendations, hallucinations, appropriate human review and how AI-generated recommendations should be presented to coders.
In other words, AI isn't simply being viewed as a fraud-detection tool. CMS is also thinking about the program-integrity risks created when healthcare organizations themselves use AI for coding and billing.
Beneficiary protections could also expand
CMS is also considering stronger protections against inappropriate beneficiary solicitation.
Current rules restrict unsolicited telephone contact by DMEPOS suppliers. CMS asked whether those restrictions should extend to email, text messages and social media, and whether similar restrictions should apply to additional types of providers and suppliers.
It is also considering ways to involve beneficiaries more directly in fraud detection, potentially contacting them about suspicious claims and asking them to verify services before or after payment.
Again, there are benefits and drawbacks. Beneficiaries can be an incredibly useful fraud-detection resource. But too much outreach, or outreach that looks suspicious itself, could create confusion, privacy concerns and yet another opportunity for scammers to impersonate CMS.
So, is CRUSH a good thing?
Conceptually, it's difficult to argue against better tools for identifying and stopping healthcare fraud. Fraud takes resources away from patients and legitimate healthcare providers, and sophisticated fraud schemes increasingly exploit weaknesses in enrollment, billing systems, beneficiary information and technology.
But stronger fraud controls are not cost-free for legitimate healthcare organizations.
More aggressive payment suspensions can affect cash flow. More enrollment requirements mean greater administrative burden. More prepayment review can delay legitimate reimbursement. Shorter filing deadlines can create operational problems. And increasingly sophisticated analytics can identify unusual billing patterns but unusual does not necessarily mean fraudulent.
This is where that tension becomes particularly important.
What's next?
For now, CRUSH is something to watch, not something requiring immediate compliance changes. CMS's regulatory agenda currently anticipates publication of the proposed CRUSH rule in October 2026.
Until then, healthcare compliance professionals shouldn't assume CRUSH is relevant only to organizations already considered high risk. The scope CMS is contemplating is considerably broader than that.
Want to read the original RFI? Go to CRUSH RFI.



Comments