Closing the DMEPOS Screening Gap in Medicare Advantage: How FACIS Helps MAOs Stay Ahead of Fraud

by | Sep 18, 2026

A HHS Office of Inspector General issue brief (OEI-02-24-00310, September 2026) delivers a clear warning to Medicare Advantage organizations: the screening gaps that let fraudulent durable medical equipment, prosthetics, orthotics, and supplies (DMEPOS) suppliers bill Original Medicare are now showing up in Medicare Advantage — and the current safety net isn’t catching them.

What OIG Found

The report zeroes in on three vulnerabilities:

  • Out-of-network suppliers get a pass:
    • MAOs check licensure and accreditation for in-network DMEPOS suppliers, but for out-of-network suppliers, the only required check is confirming they aren’t on CMS’s Preclusion List or OIG’s exclusion list. None of the six MAOs OIG interviewed verified accreditation for out-of-network suppliers, and only half checked state licenses.
  • Non-enrollment is a loophole:
    • Unlike Original Medicare, DMEPOS suppliers don’t have to enroll in Medicare to bill Medicare Advantage. Non-enrolled suppliers never go through CMS’s background checks, site visits, or fingerprinting — and OIG investigators say bad actors know it, incorporating a company and billing within days.
  • The Preclusion List is reactive, not proactive:
    • CMS has used its authority to preclude a non-enrolled supplier just once. Fifty suppliers barred from re-enrolling in Original Medicare weren’t on the Preclusion List at all — meaning they could still bill Medicare Advantage freely.

The result: Suppliers that are both out-of-network and non-enrolled billed seven times more per enrollee for orthotics than other suppliers, a pattern OIG ties directly to fraud schemes already resulting in criminal convictions.

Where Verisys FACIS Fits

OIG’s core recommendations — strengthen out-of-network checks, use the Preclusion List more effectively, and close the enrollment loophole — describe exactly the gap that comprehensive, source-agnostic screening is built to close.

  • It doesn’t depend on Medicare enrollment:
    • Because DMEPOS suppliers billing Medicare Advantage aren’t required to enroll in Medicare, CMS’s own screening pipeline never touches them. Verisys’ FACIS (Fraud and Abuse Control Information System) database isn’t tied to PECOS enrollment status — it pulls from more than 5,000 primary sources, so an MAO can screen a supplier whether or not that supplier ever applied to Medicare.
  • It goes far beyond the Preclusion List:
    • OIG found the Preclusion List catches almost nothing outside suppliers previously enrolled in Original Medicare. FACIS cross-references OIG’s LEIE, SAM, state Medicaid exclusion lists, state licensing board actions, DEA and FDA actions, DOJ and state AG enforcement news, and Medicare/Medicaid opt-outs — surfacing red flags long before (or even if) a supplier ever lands on the Preclusion List.
  • It treats in-network and out-of-network suppliers the same way:
    • The gap OIG flagged as highest-risk — out-of-network suppliers getting little to no scrutiny — exists because MAOs’ verification effort scales with contracting relationships. A screening platform applied uniformly at the point of billing, regardless of network status, removes that incentive gap entirely.
  • It verifies licensure and accreditation MAOs are currently skipping:
    • OIG found MAOs rarely check state licenses or accreditation for out-of-network suppliers. Automated primary-source license verification — confirming status, issue/expiration dates, and disciplinary history — plugs directly into that gap without adding contracting overhead.
  • It monitors continuously, not just at onboarding:
    • A supplier that’s clean today can be excluded or sanctioned tomorrow. Continuous monitoring with real-time or delta-file updates means an MAO isn’t relying on a one-time check that goes stale the moment a supplier’s status changes.

Deep Dive: How FACIS Neutralizes the Operational Vulnerability

The fundamental breakdown identified in OIG brief OEI-02-24-00310 is data blind spots caused by network-dependent and enrollment-dependent screening. FACIS eliminates these gaps through three primary operational mechanisms:

  1. Broad Primary Source Aggregation (Independent of PECOS)
    Because bad actors deliberately avoid registering with CMS to bypass PECOS background checks and site visits, standard CMS lookup tools miss them entirely. FACIS aggregates records from more than 5,000 primary sources, including state licensing boards, state Medicaid exclusions, federal sanction lists, and state Attorney General press releases. An out-of-network DMEPOS company that formed last week and has never touched Original Medicare can still be flagged if its principals or entity name are linked to prior sanctions or revoked licenses.
  2. Pre-Payment Claims Integration (Stopping “Pay and Chase”)
    Traditional credentialing happens during provider onboarding. Since out-of-network DMEPOS suppliers rarely go through onboarding, they bypass credentialing gates altogether. By integrating FACIS data directly into an MAO’s pre-adjudication claims engine via real-time APIs, every incoming DMEPOS claim triggers an automated eligibility and compliance check before payment release, instantly blocking excluded or unverified entities.
  3. Continuous Delta Monitoring
    Static monthly or annual re-credentialing allows fraudulent suppliers to operate freely between review cycles. FACIS employs continuous monitoring using daily or real-time delta files that flag immediate changes in status. If a supplier’s state license is suspended or an exclusion action is taken today, the system flags the supplier immediately, blocking claims payment tomorrow morning rather than months later.

The Verisys Implementation Roadmap for MAOs

To effectively operationalize this solution while protecting internal compliance and contracting teams from resource strain, health plans should structure implementation around four key best practices:

  1. Establish Uniform Screening Rules Across All Provider Tiers
    Best Practice: Eliminate the “Out-of-Network Pass” by configuring screening engines to enforce identical verification standards for both in-network and out-of-network DMEPOS suppliers, moving beyond basic Preclusion List checks.
  2. Automate Primary Source License & Accreditation Verification
    Best Practice: Plug state-level compliance gaps by deploying automated validation for state licensure, active status, issue/expiration dates, and disciplinary histories directly from primary sources to reduce manual review overhead.
  3. Deploy Pre-Payment APIs & Pre-Adjudication Gates
    Best Practice: Shift from post-payment recovery to upfront prevention by integrating real-time validation APIs into the claims workflow. Automatically query incoming DMEPOS claims (by NPI or billing taxonomy) against comprehensive databases like FACIS before reimbursement occurs.
  4. Activate Continuous Provider & Entity Monitoring
    Best Practice: Ensure data freshness between traditional credentialing cycles by establishing automated delta monitoring feeds that continuously track state actions, sanctions, and exclusions across primary sources in real time.

Operational Comparison

Capability

Traditional MAO Process

Recommended Best Practice Approach

Out-of-Network Oversight Bare minimum checks (OIG / Preclusion list only) Uniform, high-rigor screening across all billing tiers
Data Reliance Dependent on PECOS enrollment and CMS lists Broader aggregation across 5,000+ independent primary sources
Detection Timing “Pay and Chase” (Post-payment recovery) Pre-payment claims gating (Pre-adjudication)
Monitoring Frequency Periodic or annual spot checks Continuous monitoring via automated delta feeds

The Bottom Line

OIG’s message to CMS and MAOs is that “pay and chase” isn’t good enough — prevention has to happen before the bill is paid. For Medicare Advantage organizations trying to get ahead of that mandate without waiting on new CMS regulations or statutory authority, layering comprehensive, enrollment-independent screening like FACIS over both in-network and out-of-network DMEPOS suppliers is a practical way to close the exact gaps this report identifies.

  • Verisys

    Verisys empowers healthcare organizations with real-time, verified data solutions for compliance, credentialing, and risk mitigation. Our advanced tools ensure patient safety, streamline hiring, manage payment integrity, and enhance clinical compliance.

About the Author: Verisys

Verisys empowers healthcare organizations with real-time, verified data solutions for compliance, credentialing, and risk mitigation. Our advanced tools ensure patient safety, streamline hiring, manage payment integrity, and enhance clinical compliance.
Resource Categories

Related Compliance Resources

Ready to Elevate Your Compliance?

Contact us today to learn more about Verisys healthcare compliance solutions and how we can integrate our Gold Standard data to meet your unique needs.