Skip to main content
When claims appear under a dentist’s NPI that the dentist did not render, order, or authorize, the single action that changes the outcome is a specific, dated, signed statement denying the claims, delivered to the right contractor before the rebuttal and appeal windows close. Everything else in this guide either produces that statement or protects the deadlines it has to meet. Dentists are attractive targets precisely because they bill Medicare rarely: a stolen dental NPI can order durable medical equipment or medical services for months before anyone in the practice has a reason to look at a Medicare notice. Treat any Medicare correspondence about a dentist who doesn’t bill Medicare as a red flag, not junk mail.

Prerequisites

  • The demand letter, suspension notice, audit letter, or beneficiary report that surfaced it
  • Access to the affected dentist’s schedule, PMS, and credentialing file for the claim dates
  • The PC’s enrollment records for the payers involved
  • Healthcare regulatory counsel engaged before anything is submitted

How this surfaces

Almost never through your own billing system, because the fraudulent claims were never in it. Route any patient report of possible NPI misuse directly to the identity-theft response process. For example, a caller may report that a Medicare statement shows a back brace ordered by a dentist. Capture the beneficiary’s name, date of service, and item billed. CMS asks for those details when you contact the Medicare Administrative Contractor.

Is there a form?

Not for the denial itself. CMS runs a Victimized Provider Project for exactly this situation, and it routes you to your UPIC and your MAC, neither of which publishes a form for the statement. The submission is a free-form signed writing, and its quality is entirely yours to control. That is why the format matters, and why we publish one. Forms do exist for the actions that follow it:
XLSX

Fill-in workbook

Provider identity theft denial packet

Six sheets: a deadline calculator that takes the date on your notice and tells you what is due when, the declaration itself executed under 28 U.S.C. § 1746, a schedule of disputed claims, an authorized-billers exhibit, and a contact log. Fill in the shaded cells.

Excel / Google Sheets6 sheetsUpdated August 2026

Download the workbook
Open it in Google Sheets or Excel and complete the deadline calculator first. Some response windows are only 15 days and run while the investigation is still underway. It is a template, not a filing. Counsel should review and transmit it.

Steps

1

Fix the date you learned, and preserve everything

Before anything else, record the date and the source. That date anchors every later argument about your diligence, and it is the first thing an investigator, a payer, and a plaintiff will ask for.Preserve the notice, envelope, caller’s account, and system alert. Capture the current NPPES or PECOS record before making a correction because the unauthorized change is evidence.
2

Do not deactivate the NPI reflexively

Deactivation is usually the wrong first move, and it is frequently the advice you will be given.Deactivation does not erase previously submitted fraudulent claims or an overpayment demand. It may interrupt legitimate claims, active payer enrollments, and pending preauthorizations across every entity that bills under the dentist’s NPI. A new number can also require rebuilding the credentialing chain.The NPI is designed to be permanent; a deactivated NPI is never reassigned to anyone else. Deactivation and reissuance is a real remedy in a genuine, unrecoverable compromise, but it is an endgame decision made with counsel and your MAC, not a reflex on day one. What you should do immediately is lock the accounts: change NPPES, PECOS, and I&A credentials, confirm multi-factor authentication is on, and review authorized surrogates and delegated users.
3

Establish what is actually yours

Define the claim scope before issuing a denial. For each claim or date range, review the dentist’s schedule, PMS, license status, location, and every legitimate billing entity in the group. Include medical claims properly billed for dental-related work, such as sleep appliances or oral surgery. See Bill medical for dental work.Three buckets come out of this: not ours, ours and correct, and ours and wrong. You will very likely have some of the third.If part of it turns out to be yours and wrong, that is an overpayment on its own clock. The report-and-return obligation under 42 U.S.C. § 1320a-7k(d) applies to that portion regardless of what happened to the rest, and the identity theft does not toll it. Split the tracks and run both. See Report and return overpayments.
4

Write the denial statement

This is the deliverable. See What the denial statement must contain below for the substance; it is the artifact that every subsequent step attaches.Draft it with counsel. It goes to a federal program, it will be relied on, and a materially false statement in it is itself a federal offense under 18 U.S.C. § 1035.
5

Contact the UPIC through the Victimized Provider Project

CMS runs a Victimized Provider Project for exactly this situation, acknowledging that providers whose Medicare identities are stolen are “victimized twice”, once by the theft and once by the financial consequences.1The route is your Unified Program Integrity Contractor (UPIC), the CMS fraud investigator for your region. Report the suspicious activity, submit the denial statement, and respond to the UPIC’s inquiries, including interviews, after verifying the investigator’s credentials.
Ask the assistant which contractor is yours. There are five UPIC jurisdictions and more than a dozen MAC jurisdictions, and Part A/B and DME are frequently different contractors for the same state. Rather than reproduce assignments here that move between contract cycles, tell the assistant on this site which state your PC is enrolled in and it will hand you the current CMS directory entries for both, plus your state’s Medicaid Fraud Control Unit and program integrity director.
The UPIC investigates and reports its findings to CMS. That finding is what unwinds the overpayment.
6

Contact the MAC in parallel

Your Medicare Administrative Contractor is a different party with different levers: it issued the demand letter, it holds the enrollment record, and it controls recoupment.Ask it to confirm whether any recent enrollment changes were made, give it the beneficiary names and dates from any patient reports, and put the denial statement in its file. CMS’s own guidance is that beneficiary information “will help them investigate.”
7

Protect the deadlines while the investigation runs

The investigation will outlast your appeal windows. Do not wait for it.File the rebuttal and the redetermination. They do different things.
8

Run the Medicaid track separately

Medicaid is not a copy of Medicare here, and the difference is unfavorable. See The Medicaid track below.
9

Report the theft to law enforcement and HHS OIG

CMS explicitly recommends a police report. File one; the report number is evidence that the denial was contemporaneous rather than constructed after a demand letter arrived.Report to HHS OIG through its fraud hotline and online reporting form. If personal identifiers such as an SSN were involved, file with the FTC at IdentityTheft.gov as well.
10

Clean up the tax and Treasury consequences

A fraudulent 1099 reports income to the IRS that the entity never received, and an unpaid overpayment gets referred to the Department of the Treasury for collection.Address both records. Ask the MAC to correct or withdraw the 1099 after the UPIC finding, and report business identity theft to the IRS when appropriate. Form 14039-B is the business identity-theft affidavit for misuse of an EIN.4 Coordinate with your CPA rather than reporting income the group did not receive.
11

Notify the other payers and the licensing board

Notify dental payers that credential the same NPI, including relevant Delta Dental companies, national carriers, and Medicaid dental benefit administrators. Use a consistent written statement so they can flag unauthorized claims before a separate credentialing action begins.Whether a report to the state licensing board is required or merely advisable depends on the state and on what happened. Ask counsel, but do not let the board learn about it from a payer.
12

Harden and assign the monitoring

Close the hole and give the watching a named owner. See Verify it worked.

What the denial statement must contain

The point of the statement is to be specific enough to be relied on and narrow enough to survive scrutiny. A vague blanket denial is worth very little; an overbroad one is worse than nothing, because a single claim that turns out to be legitimate discredits the whole document. Sign it under penalty of perjury. Federal law permits an unsworn declaration in place of a notarized affidavit where it is dated and states, in substance, “I declare under penalty of perjury that the foregoing is true and correct”, 28 U.S.C. § 1746.3 That form is available anywhere, immediately, and carries the same weight. Identify yourself precisely. Full legal name as enrolled, NPI, state license number(s), the PC’s legal name and TIN, and the Medicare and Medicaid enrollment identifiers at issue. Scope the denial to specific claims. List claim-control numbers, dates of service, beneficiary identifiers, billing entity, and items or services. If detailed claim data is unavailable, identify the date range and payer, state the scope of the denial, and request the full claim list. Make three separate denials, because they are three different assertions. That you did not render the services. That you did not order, refer, prescribe, or certify medical necessity for them. That you did not authorize any person or entity to submit claims using your identifiers. State affirmatively what is true. Explain where the dentist practiced on the relevant dates, their actual scope of practice, which entities were authorized to bill under the NPI, and whether any employment, contractual, ownership, or referral relationship existed with the submitting entity. This factual account gives the payer more to verify than a bare denial. Attach the evidence. Schedule or PMS extracts for the dates, the list of authorized billing entities, the police report number, the date and manner in which you learned, and any NPPES or PECOS change records. Say what you have already done. UPIC contact, MAC contact, police report, credential lockdown, OIG report, with dates. This is the diligence record. Deny only what you have actually verified, and say so about the rest. “I did not render or order these services” for claims you have checked, and “I have not yet been able to review claims X through Y and will supplement” for the rest, is a stronger document than a confident denial of everything. A false statement in connection with the delivery of or payment for health care benefits is a federal crime under 18 U.S.C. § 1035, carrying up to five years. The statement is a legal instrument, not a letter of complaint. It should be drafted and transmitted by counsel.

The Medicaid track

Medicaid runs on a different rule and it is harsher, so treat it as its own workstream rather than a cc: on the Medicare one. The suspension is mandatory, not discretionary. Under 42 C.F.R. § 455.23(a)(1), the State Medicaid agency must suspend all Medicaid payments to a provider once it determines a credible allegation of fraud exists for which an investigation is pending, unless it has good cause not to suspend, or to suspend only in part. Medicare’s parallel authority at § 405.371(a)(2) says CMS may. That word is the difference between a suspension you can argue against and one the state has to impose first and reconsider later.2 The term “credible allegation of fraud” does not itself identify who submitted the claims. Under 42 C.F.R. § 455.2, an allegation may come from sources such as hotline tips, claims-data analysis, audit patterns, or law enforcement and must be verified by the state as having indicia of reliability. Good cause is the target, and it runs on written evidence. The exceptions at § 455.23(e) and (f) let the State decline to suspend, lift a suspension, or suspend only in part. One of them turns expressly on the State determining, based on written evidence, that the suspension should be removed. Your denial statement, the police report, the UPIC engagement, and the schedule extracts are that written evidence. Assemble them for the state agency in the same package. Notice is fast, and can be withheld. The agency must send notice within 5 days of suspending, unless law enforcement asks in writing that notice be temporarily withheld. So a suspension may be the first thing you learn, and it may arrive after the investigation has been running for a while. The state Medicaid agency’s program-integrity unit handles the payment suspension and good-cause determination. The Medicaid Fraud Control Unit investigates and prosecutes. Each of the 50 states, D.C., Puerto Rico, and the Virgin Islands has an MFCU, often within the Attorney General’s office, and 42 C.F.R. part 1007 requires separation from the Medicaid agency. Send the factual denial to the appropriate recipients, but have counsel manage contact with the law-enforcement unit. A Medicaid suspension can pull Medicare down with it. Under 42 C.F.R. § 405.371(a)(4), CMS may suspend Medicare payment on the basis that the provider is subject to a Medicaid payment suspension. And under § 455.416, State Medicaid agencies must deny or terminate enrollment for a provider terminated under Medicare or another state’s Medicaid or CHIP program. For a multi-state group this is the compounding risk: an adverse action against one dentist in one state can propagate to the federal program and, if it escalates from suspension to termination, to every other state where that dentist is enrolled. See Why multi-state groups have one PC per state.

If enrollment is revoked

A revocation under 42 C.F.R. § 424.535(a)(8) is generally effective 30 days after CMS mails notice and carries a reenrollment bar of at least one year.
  • Reconsideration under 42 C.F.R. § 498.22 must be filed within 60 days after receipt of the initial determination. Receipt is presumed five days after the date on the letter, so MACs administer the period as 65 days from the letter date. Calendar from the letter date rather than the date it reached the office. This is the route for an identity-theft revocation.
  • A corrective action plan under 42 C.F.R. § 405.809 is available only for revocations based on noncompliance, and MACs administer its window as 35 days from the letter date. It is not the path here, and pursuing it instead of a reconsideration burns the reconsideration window.
  • Beyond reconsideration: ALJ hearing, then Departmental Appeals Board review, then judicial review.
Tell your dental payers and any hospital or surgery center where the dentist holds privileges. Many contracts condition participation on federal program standing, and the discovery is much worse than the disclosure.

Verify it worked

  • Date and source of discovery recorded
  • Notices, envelopes, and system records preserved
  • NPPES, PECOS, and I&A credentials rotated; MFA on; surrogates and delegated users reviewed
  • NPI not deactivated absent a considered decision with counsel and the MAC
  • Every claim sorted into not-ours / ours-and-correct / ours-and-wrong
  • 60-day clock started on anything in the third bucket
  • Denial statement signed under 28 U.S.C. § 1746, scoped to specific claims
  • UPIC contacted through the Victimized Provider Project; statement submitted
  • MAC contacted; beneficiary names and dates provided; statement in the file
  • Rebuttal filed within the § 405.374 window
  • Redetermination filed by day 30 of the demand letter
  • Medicaid: good-cause package delivered to the state program integrity unit
  • Police report filed; number recorded
  • HHS OIG report filed; FTC report if personal identifiers were exposed
  • 1099 and Treasury referral addressed with the MAC and the CPA
  • Dental payers and Medicaid DBAs notified in writing
  • Licensing board question resolved with counsel
  • A named owner assigned for ongoing NPI monitoring across all entities

Common failure modes

Sources

  1. CMS Center for Program Integrity, Victimized Provider Project; CMS, Victimized Provider Project points of contact (state-by-state UPIC contact list). Overpayment mechanics, recoupment at day 41, interest from day 31, and the five appeal levels, from CMS, Medicare Overpayments (MLN006379, July 2025), and the limitation on recoupment at 42 U.S.C. § 1395ddd(f)(2). Rebuttal: 42 C.F.R. § 405.374.
  2. Medicaid suspension: 42 C.F.R. § 455.23; definitions, 42 C.F.R. § 455.2; Medicare suspension, 42 C.F.R. § 405.371; Medicaid enrollment termination, 42 C.F.R. § 455.416; Medicaid Fraud Control Units, 42 C.F.R. part 1007 and HHS OIG, Medicaid Fraud Control Units. CMS, Medicaid Payment Suspension Toolkit.
  3. Unsworn declarations under penalty of perjury, 28 U.S.C. § 1746. False statements relating to health care matters, 18 U.S.C. § 1035. Report-and-return obligation, 42 U.S.C. § 1320a-7k(d).
  4. Enrollment revocation and appeals: 42 C.F.R. § 424.535; 42 C.F.R. § 498.22; 42 C.F.R. § 405.809; deactivation rebuttals, 42 C.F.R. § 424.546. For how MACs administer the CAP, reconsideration, and rebuttal windows, see Noridian, Provider Enrollment Reconsiderations, CAPs, and Rebuttals. Appeal forms: CMS-20027 (redetermination) and CMS-20033 (reconsideration). Reporting: HHS OIG, Report Fraud; FTC, IdentityTheft.gov. Business identity theft: IRS, Report Identity Theft for a Business (Form 14039-B). Contractor directories: CMS, Review Contractor Directory, Interactive Map and MAC directory.
Last modified on August 21, 2026