US · guidance
CMS Pub. 100-08, ch. 10, § 10.2.5.2
Fraud Level Indicators for DMEPOS Suppliers - Development and
Use
(Rev. 11682; Issued: 11-04-2022; Effective: 12-05-2022; Implementation: 12-05-2022)
A. General Information
The contractor shall perform a fraud potential analysis of all DMEPOS applicants and current
DMEPOS suppliers. The fraud level indicator shall represent the potential for fraud and/or
abuse. The contractor shall use four fraud level indicator codes as follows:
• Low Risk (e.g., national drug store chains)
• Limited Risk (e.g., prosthetist in a low fraud area)
• Medium Risk (e.g., midsize general medical supplier in a high fraud area)
• High Risk (e.g., very small space diabetic supplier with low inventory in a high fraud area
whose owner has previously had a chapter 7 bankruptcy). High fraud areas shall be
determined by contractor analysis with concurrence of the contractor project officer.
(NOTE: These risk categories are in addition to, and not in lieu of, those specified in 42 CFR §
424.518.)
In assessing a fraud level indicator, the contractor shall consider such factors as:
• Experience as a DMEPOS supplier with other payers
• Prior Medicare experience
• The geographic area
• Fraud potential of products and services listed
• Site visit results
• Inventory observed and contracted
• Accreditation of the supplier
After a fraud level indicator is assigned and the DMEPOS supplier is enrolled, the contractor
shall establish a DMEPOS Review Plan based on the fraud level assessment. The DMEPOS
Review Plan shall contain information regarding:
• Frequency of unscheduled site visits
• Maximum billing amounts before recommendation for prepay medical review
• Maximum billing spike amounts before recommendation for payment suspensions/prepay
medical review, etc.
The fraud level indicator shall be updated based upon information obtained through the Medicare
enrollment process, such as reported changes of information.
Information obtained by the Office of Inspector General (OIG), CMS (including CMS satellite
office), and/or a Unified Program Integrity Contractor (UPIC) shall be reported to the contractor
project officer. The contractor shall update the fraud level indicator based on information
obtained by the OIG, CMS (including CMS satellite office), and/or a UPIC only after the review
and concurrence of the contractor project officer.
In addition, the contractor shall monitor and assess geographic trends that indicate or
demonstrate that one geographic area has a higher potential for having fraudulent suppliers.
B. When a DMEPOS Fraud Level Indicator Differs from Risk Screening Category under
42 CFR § 424.518
The fraud level indicator described in this subsection is unrelated to the risk screening categories
required under 42 CFR § 424.518. Under § 424.518(c)(1)(ii), for example, newly enrolling
DMEPOS suppliers are assigned to the “high” risk screening category. Such DMEPOS suppliers
are therefore subject to screening activities that correspond to the “high” risk screening category,
including an on-site visit and a fingerprint-based criminal background check for all individuals
who maintain a 5 percent or greater direct or indirect ownership interest in the supplier. (See §
424.518(c)(2).) The on-site visits that the contractor conducts are responsive to the requirement
at § 424.518(c)(2)(i) for a site visit and include gathering information concerning fraud level
indicator assignment as required in this subsection. A DMEPOS supplier therefore has both a
risk-based screening category assignment pursuant to requirements under § 424.518, and a
separate fraud level indicator based upon the guidance in this subsection.
C. Fraud Level Indicator Standards
The contractor shall have documented evidence that it has, at a minimum, met the following
requirements:
• Assigned an appropriate fraud level indicator for at least 95 percent of all DMEPOS suppliers
upon initial enrollment or revalidation. The fraud level indicator shall accurately reflect the
risk the supplier poses to the Medicare program based on pre-defined criteria above.
• Updated the DMEPOS fraud level indicator for each enrolled DMEPOS supplier on an
annual basis.
D. Alert Codes for DMEPOS Suppliers
The contractor shall receive and maintain the following “alert indicators” from the DME MACs
and UPICs:
Alert Code and Definition
A - Possible fraudulent or abusive claims identified
B - Overpayments
D - Violations of disclosure of ownership requirements
E - Violations of participation agreements
L - Suspended by contractor outside alert code process
M - Supplier is going through claims appeal process
The contractor shall append the supplier file and transfer to the DME-MACs and/or UPICs the
following alert codes in the following circumstances:
Alert Code and Definition
C - Violations of supplier standards
F - Excluded by the OIG or debarred per the System for Award Management
H - Meets supplier standards; however, the contractor recommends increased scrutiny by the
contractor (initiated by the contractor only)
N - Supplier being investigated under the "Do Not Forward" initiative (initiated by contractor
only)
Q - Low Risk Fraud Level Indicator
R - Limited Risk Fraud Level Indicator
S - Medium Risk Fraud Level Indicator
T - High Risk Fraud Level Indicator
The contractor shall append an Alert Code "H" for any supplier that meets present supplier
standards but appears suspect in one of the areas that are verified by the contractor. This alert
code notifies the contractors that a supplier may be inclined to submit a high percentage of
questionable claims.
The contractor shall share the above information with the DME MACs and/or UPICs by sending
alerts within 7 calendar days after identification of a supplier having common ownership or
business ties with a sanctioned or suspect supplier for their research and/or action. The
contractor also shall forward alert codes submitted by the contractors with the other contractors
within 7 calendar days after receipt.
History
(Rev. 11682; Issued: 11-04-2022; Effective: 12-05-2022; Implementation: 12-05-2022)
Provenance
- Source
- cms.gov
- Retrieved
- 2026-08-25
- Edition
- iom-2026-08-25
- Content hash
3fe1ac264ca17a040a1cda127e1d00fc6d104246fbd9195313a336e9258a6d3c
The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.
Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.