Why NPI data is public
An NPI is a public identifier rather than a secret credential. HIPAA administrative simplification established it as the standard unique health identifier for providers, implemented at 45 C.F.R. part 162, subpart D.1 Health care transactions rely on it to identify providers consistently. CMS publishes the NPPES registry as a public, downloadable file containing active NPIs and associated information such as provider names, taxonomies, and practice addresses. Public access lets payers, clearinghouses, and referring practices verify providers, but it also gives a fraudster one of the inputs needed for identity theft. Treat the NPI as a public identifier rather than proof of identity. Protect the accounts and records that control access, including NPPES, PECOS, the CMS Identity & Access account, EDI submitter credentials, payer portals, enrollment records, and payment instructions.Rendering and ordering misuse
Two very different things get called “billing under my NPI.”
Ordering or referring misuse may not appear in the provider’s cash reconciliation or billing system because another supplier submits the claim and receives payment. In that situation, the stolen NPI functions as the purported order or referral on someone else’s claim.
Large schemes involving durable medical equipment, genetic testing, and telehealth consults often harvest physicians’ NPIs because the claims require an ordering physician. Dentists face a related pattern. A dentist’s Type 1 NPI is also public and can be used for enrollment fraud or rendering-provider misattribution. In dentistry, the better-documented example is misattribution inside a group: Medicaid claims naming a dentist who did not perform the work. The MB2 and HQRC False Claims Act settlements included allegations or admissions of that conduct. A dentist whose number is used this way may face the same payer and enrollment machinery even when their own group submitted the claim. See Billing compliance basics.
Documented enforcement scale
In the 2025 National Health Care Fraud Takedown, DOJ charged 324 defendants in schemes involving more than 10.6 billion in claims for urinary catheters and other DME using stolen beneficiary and provider identities.2 GAO’s 2026 review of CMS fraud analytics describes the CMS side of the same problem: providers attempted to bill more than $4 billion for urinary catheters never supplied during 2023–2024; CMS suspended payments to and later revoked the enrollment of 15 providers, preventing over 99 percent of the payments. Across fiscal years 2022–2024, CMS imposed payment suspensions on 1,160 providers and revocations or deactivations on 569.3 CMS uses payment suspension, deactivation, and revocation to stop suspect billing. Those actions attach to enrollment records and identifiers, so an innocent provider may need to establish the misuse before the agency has resolved who acted with fraudulent intent.Four administrative consequences
1. Overpayment demand and recoupment
If claims paid out under your NPI, the enrolled provider of record is who Medicare bills to get it back. A demand letter starts a clock that does not care whose signature was forged:
Filing a redetermination by day 30 stops recoupment before it starts; filing a reconsideration with the QIC within 60 days of the redetermination decision stops it again. This statutory limit on recoupment appears at 42 U.S.C. § 1395ddd(f)(2) and applies only to the first two appeal levels. At level three and beyond, recoupment proceeds during the appeal. Interest continues to accrue and is refunded with the principal if the provider prevails.4
2. Medicare and Medicaid payment suspension
Medicaid and Medicare use different suspension rules. That distinction matters for a dental group whose Medicaid volume is substantial and whose Medicare volume may be limited. Review the mandatory Medicaid suspension framework below against the group’s actual payer mix.
A credible allegation of fraud is defined at 42 C.F.R. § 455.2 as an allegation from any source, including hotline tips, claims data mining, audit patterns, or law enforcement, that has been verified by the state and bears indicia of reliability. The definition does not require a finding about who actually submitted the claims.5
The good-cause exceptions at § 455.23(e) and (f) may support relief in this situation. The state may find good cause when it determines, based on written evidence, that the suspension should be removed or imposed only in part. That makes a documented denial statement important.
A Medicaid suspension can cascade into Medicare. Under 42 C.F.R. § 405.371(a)(4), CMS may suspend Medicare payment because the provider is subject to a Medicaid payment suspension under § 455.23(a)(1). A single state’s determination can therefore stop payment on the federal side as well.
Separately, § 455.416 requires state Medicaid agencies to deny or terminate enrollment for a provider terminated under Medicare or another state’s Medicaid or CHIP program. Termination differs from suspension, but it can create multistate enrollment consequences.
3. Revocation of enrollment
42 C.F.R. § 424.535(a)(8) authorizes revocation for abuse of billing privileges. Examples include claims for services that could not have been furnished because the beneficiary was deceased, the provider was not in the state, or required equipment was absent. It also covers an established pattern of improper claims.6 Revocation is generally effective 30 days after CMS mails notice and carries a reenrollment bar of at least 1 year, up to 10 years, and up to 20 years for a second revocation. Other payer, Medicaid, and facility applications may ask about adverse federal enrollment actions, so the effect can extend beyond Medicare. Appeal rights run under 42 C.F.R. part 498: reconsideration within 60 days after receipt of the initial determination, followed by an ALJ hearing, Departmental Appeals Board review, and judicial review. A corrective action plan under 42 C.F.R. § 405.809 is available only for revocations based on noncompliance. It is not the route for a revocation based on billing abuse, which is how an identity-theft revocation may be characterized.74. Tax and Treasury consequences
CMS itself describes victimized providers as being “victimized twice,” and enumerates the second injury: demand letters, debt referral to the Department of the Treasury, Form 1099 issued for funds never received, and deductions from Social Security payments.8 An incorrect Form 1099 can report income under the victim’s TIN even though the victim did not receive the funds. Address the tax record separately from the payer appeal and overpayment dispute.Building the record that the claims were unauthorized
A payer may initially have no information showing that the enrolled provider did not authorize a claim or order. The transaction can contain valid identifiers while omitting the facts needed to identify the impersonation. The provider’s report supplies that missing record. The response rests on these legal rules: Document what the provider knew and did. The False Claims Act defines “knowingly” at 31 U.S.C. § 3729(b)(1) to include actual knowledge, deliberate ignorance, and reckless disregard.9 A prompt written denial, fraud report, preservation record, and cooperation log help show that the provider did not authorize the claims and responded after learning of them. Ignoring notices can complicate that record. The 60-day rule has no identity-theft carve-out. If any part of what surfaced is actually yours and actually wrong, the report-and-return obligation at 42 U.S.C. § 1320a-7k(d) applies to that part on its own timetable. See Report and return overpayments. A specific, dated written denial supports the good-cause request, rebuttal, appeal, and fraud investigation. It should identify the disputed claims or orders, state that they were not authorized, describe the provider’s actual location or services where relevant, and preserve supporting evidence. See Respond to NPI identity theft.What the fraudster is charged with
These statutes help explain the evidence investigators may request from a victim provider.
In Dubin v. United States, 599 U.S. 110 (2023), the Supreme Court interpreted § 1028A narrowly. A defendant “uses” a means of identification “in relation to” a predicate offense when the identity misuse is central to what makes the conduct criminal, rather than incidental to the billing method. Dubin involved psychological testing that had been performed but was billed at an inflated rate using a real patient’s identifier.10
The DSO-PC dimension
A group structure multiplies the attack surface and changes who is responsible for watching it. You have two classes of NPI, and both are exposed. Each dentist holds a Type 1 individual NPI that travels with them across every entity and state; each PC holds a Type 2 organizational NPI. A Type 1 compromise follows the dentist into every PC they are credentialed under. A Type 2 compromise is contained to one entity but implicates that entity’s entire payer book. See Get an NPI. Assign responsibility for monitoring and response. A dentist and PC biller may not see claims submitted by an outside actor. A DSO that receives correspondence or supports several entities may be positioned to identify patterns across locations. If the DSO performs this service, describe it in the MSA, assign an owner, and define escalation to the affected dentist and PC. Monitor enrollment correspondence. Demand letters, revocation notices, and rebuttal deadlines may arrive at the address in the enrollment record. Route mail for every entity and service location to a monitored intake with date stamping and escalation. See Maintain corporate formalities. Map individual and entity exposure separately. A dentist-owner may also appear on Medicaid and commercial payer disclosures or enrollments. An adverse action against the individual can affect the practice’s enrollment or contracts, but the result depends on the payer, program, role, and action. See The friendly PC and Vet a friendly dentist.Sources
- HIPAA administrative simplification, standard unique health identifier for health care providers, 45 C.F.R. part 162, subpart D; National Provider System duties including deactivation, 45 C.F.R. § 162.408; provider implementation specifications, 45 C.F.R. § 162.410. NPPES data is published by CMS as a public downloadable file.
- U.S. Department of Justice, 2025 National Health Care Fraud Takedown (June 2025), 324 defendants, over 10.6 billion in claims using the stolen identities of over one million Americans. Summarized in Womble Bond Dickinson, 2025 National Health Care Fraud Takedown Sets Record as Largest in U.S. History, and Mintz, Health Care Fraud Enforcement Developments: the 2025 Takedown.
- U.S. Government Accountability Office, Medicare: CMS’s Use of Data Analytics to Identify and Prevent Fraud, GAO-26-107799, over $4 billion attempted in urinary catheter billing 2023–2024; 15 providers suspended and revoked; over 99% of payments prevented; 1,160 payment suspensions and 569 revocations or deactivations in FY 2022–2024.
- Limitation on recoupment, 42 U.S.C. § 1395ddd(f)(2); recoupment at day 41 and interest at day 31, CMS, Medicare Overpayments (MLN006379, July 2025) and CMS Medicare Financial Management Manual, Pub. 100-06, ch. 4.
- Definitions, 42 C.F.R. § 455.2; Medicaid suspension of payments in cases of fraud, 42 C.F.R. § 455.23; Medicare suspension bases, 42 C.F.R. § 405.371; notice, § 405.372; opportunity for rebuttal, 42 C.F.R. § 405.374. See also CMS, Medicaid Payment Suspension Toolkit.
- Revocation of enrollment, 42 C.F.R. § 424.535, including (a)(8) abuse of billing privileges, the effective-date rules, and the reenrollment bar.
- Appeals procedures, 42 C.F.R. part 498; reconsideration and its 60-day filing period, 42 C.F.R. § 498.22; appeal rights of prospective providers and suppliers, 42 C.F.R. § 498.5; reinstatement following corrective action, 42 C.F.R. § 405.809.
- CMS Center for Program Integrity, Victimized Provider Project, describing demand letters, Treasury debt referral, Forms 1099 for funds never received, and Social Security deductions.
- False Claims Act, 31 U.S.C. §§ 3729–3733; the knowledge standard at § 3729(b)(1). Report-and-return obligation, 42 U.S.C. § 1320a-7k(d).
- Dubin v. United States, 599 U.S. 110 (2023) (Sotomayor, J., unanimous). Criminal statutes: 18 U.S.C. §§ 1028, 1028A, 1035, 1347; 42 U.S.C. § 1320a-7b(a).