Bindinglaw

US · guidance

CMS Pub. 100-08, ch. 10, § 10.2.5.2

Fraud Level Indicators for DMEPOS Suppliers - Development and

activein force · 2026-08-25 – presentas-observed

Use

(Rev. 11682; Issued: 11-04-2022; Effective: 12-05-2022; Implementation: 12-05-2022)

A. General Information

The contractor shall perform a fraud potential analysis of all DMEPOS applicants and current

DMEPOS suppliers. The fraud level indicator shall represent the potential for fraud and/or

abuse. The contractor shall use four fraud level indicator codes as follows:

• Low Risk (e.g., national drug store chains)

• Limited Risk (e.g., prosthetist in a low fraud area)

• Medium Risk (e.g., midsize general medical supplier in a high fraud area)

• High Risk (e.g., very small space diabetic supplier with low inventory in a high fraud area

whose owner has previously had a chapter 7 bankruptcy). High fraud areas shall be

determined by contractor analysis with concurrence of the contractor project officer.

(NOTE: These risk categories are in addition to, and not in lieu of, those specified in 42 CFR §

424.518.)

In assessing a fraud level indicator, the contractor shall consider such factors as:

• Experience as a DMEPOS supplier with other payers

• Prior Medicare experience

• The geographic area

• Fraud potential of products and services listed

• Site visit results

• Inventory observed and contracted

• Accreditation of the supplier

After a fraud level indicator is assigned and the DMEPOS supplier is enrolled, the contractor

shall establish a DMEPOS Review Plan based on the fraud level assessment. The DMEPOS

Review Plan shall contain information regarding:

• Frequency of unscheduled site visits

• Maximum billing amounts before recommendation for prepay medical review

• Maximum billing spike amounts before recommendation for payment suspensions/prepay

medical review, etc.

The fraud level indicator shall be updated based upon information obtained through the Medicare

enrollment process, such as reported changes of information.

Information obtained by the Office of Inspector General (OIG), CMS (including CMS satellite

office), and/or a Unified Program Integrity Contractor (UPIC) shall be reported to the contractor

project officer. The contractor shall update the fraud level indicator based on information

obtained by the OIG, CMS (including CMS satellite office), and/or a UPIC only after the review

and concurrence of the contractor project officer.

In addition, the contractor shall monitor and assess geographic trends that indicate or

demonstrate that one geographic area has a higher potential for having fraudulent suppliers.

B. When a DMEPOS Fraud Level Indicator Differs from Risk Screening Category under

42 CFR § 424.518

The fraud level indicator described in this subsection is unrelated to the risk screening categories

required under 42 CFR § 424.518. Under § 424.518(c)(1)(ii), for example, newly enrolling

DMEPOS suppliers are assigned to the “high” risk screening category. Such DMEPOS suppliers

are therefore subject to screening activities that correspond to the “high” risk screening category,

including an on-site visit and a fingerprint-based criminal background check for all individuals

who maintain a 5 percent or greater direct or indirect ownership interest in the supplier. (See §

424.518(c)(2).) The on-site visits that the contractor conducts are responsive to the requirement

at § 424.518(c)(2)(i) for a site visit and include gathering information concerning fraud level

indicator assignment as required in this subsection. A DMEPOS supplier therefore has both a

risk-based screening category assignment pursuant to requirements under § 424.518, and a

separate fraud level indicator based upon the guidance in this subsection.

C. Fraud Level Indicator Standards

The contractor shall have documented evidence that it has, at a minimum, met the following

requirements:

• Assigned an appropriate fraud level indicator for at least 95 percent of all DMEPOS suppliers

upon initial enrollment or revalidation. The fraud level indicator shall accurately reflect the

risk the supplier poses to the Medicare program based on pre-defined criteria above.

• Updated the DMEPOS fraud level indicator for each enrolled DMEPOS supplier on an

annual basis.

D. Alert Codes for DMEPOS Suppliers

The contractor shall receive and maintain the following “alert indicators” from the DME MACs

and UPICs:

Alert Code and Definition

A - Possible fraudulent or abusive claims identified

B - Overpayments

D - Violations of disclosure of ownership requirements

E - Violations of participation agreements

L - Suspended by contractor outside alert code process

M - Supplier is going through claims appeal process

The contractor shall append the supplier file and transfer to the DME-MACs and/or UPICs the

following alert codes in the following circumstances:

Alert Code and Definition

C - Violations of supplier standards

F - Excluded by the OIG or debarred per the System for Award Management

H - Meets supplier standards; however, the contractor recommends increased scrutiny by the

contractor (initiated by the contractor only)

N - Supplier being investigated under the "Do Not Forward" initiative (initiated by contractor

only)

Q - Low Risk Fraud Level Indicator

R - Limited Risk Fraud Level Indicator

S - Medium Risk Fraud Level Indicator

T - High Risk Fraud Level Indicator

The contractor shall append an Alert Code "H" for any supplier that meets present supplier

standards but appears suspect in one of the areas that are verified by the contractor. This alert

code notifies the contractors that a supplier may be inclined to submit a high percentage of

questionable claims.

The contractor shall share the above information with the DME MACs and/or UPICs by sending

alerts within 7 calendar days after identification of a supplier having common ownership or

business ties with a sanctioned or suspect supplier for their research and/or action. The

contractor also shall forward alert codes submitted by the contractors with the other contractors

within 7 calendar days after receipt.

History

(Rev. 11682; Issued: 11-04-2022; Effective: 12-05-2022; Implementation: 12-05-2022)

Provenance

Source
cms.gov
Retrieved
2026-08-25
Edition
iom-2026-08-25
Content hash
3fe1ac264ca17a040a1cda127e1d00fc6d104246fbd9195313a336e9258a6d3c
View the official source →

The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.

Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.

Coverage · API docs

Bindinglaw

Point-in-time US law with the receipt attached. Source URL, retrieval time, content hash, and validity dates on every answer.

curl api.binding.law/v1/law/coverage

© 2026 binding.law · a Jubal, Inc. productAttorneys and firms never pay. Ever.