> ## Documentation Index
> Fetch the complete documentation index at: https://dso.getlemma.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Respond to NPI identity theft

> What to do when someone bills under your NPI: the written denial that does the work, the UPIC and MAC route, the Medicaid track, and the deadlines that expire while you investigate.

When claims appear under a dentist's NPI that the dentist did not render, order, or authorize, the single action that changes the outcome is a **specific, dated, signed statement denying the claims**, delivered to the right contractor before the rebuttal and appeal windows close. Everything else in this guide either produces that statement or protects the deadlines it has to meet.

Dentists are attractive targets precisely because they bill Medicare rarely: a stolen dental NPI can order durable medical equipment or medical services for months before anyone in the practice has a reason to look at a Medicare notice. Treat any Medicare correspondence about a dentist who doesn't bill Medicare as a red flag, not junk mail.

## Prerequisites

* The demand letter, suspension notice, audit letter, or beneficiary report that surfaced it
* Access to the affected dentist's schedule, PMS, and credentialing file for the claim dates
* The PC's enrollment records for the payers involved
* Healthcare regulatory counsel engaged before anything is submitted

## How this surfaces

Almost never through your own billing system, because the fraudulent claims were never in it.

| Signal                                                                                                                 | What it usually means                      |
| ---------------------------------------------------------------------------------------------------------------------- | ------------------------------------------ |
| A patient or a beneficiary's family calls about a service on their **Medicare Summary Notice** that names your dentist | Ordering/referring misuse, in flight       |
| A **demand letter** from the MAC for an overpayment you never received                                                 | The scheme already paid out                |
| A **payment suspension notice**, Medicare or Medicaid                                                                  | An investigation is already open           |
| A **Form 1099** reporting income the entity never received                                                             | Payment went somewhere else under your TIN |
| Unexplained **prior-authorization or audit requests** for services you don't provide                                   | Someone is billing them in your name       |
| A payer's **credentialing** or revalidation contact citing claims you don't recognize                                  | Same                                       |
| An unrecognized change to the **NPPES or PECOS** record                                                                | The account itself is compromised          |

Route any patient report of possible NPI misuse directly to the identity-theft response process. For example, a caller may report that a Medicare statement shows a back brace ordered by a dentist. Capture the beneficiary's name, date of service, and item billed. CMS asks for those details when you contact the Medicare Administrative Contractor.

## Is there a form?

**Not for the denial itself.** CMS runs a Victimized Provider Project for exactly this situation, and it routes you to your UPIC and your MAC, neither of which publishes a form for the statement. The submission is a free-form signed writing, and its quality is entirely yours to control. That is why the format matters, and why we publish one.

Forms do exist for the actions that follow it:

| Instrument                                             | Form                         | Note                                                                 |
| ------------------------------------------------------ | ---------------------------- | -------------------------------------------------------------------- |
| Redetermination, appeal level 1                        | **CMS-20027**                | Or the MAC's own equivalent                                          |
| Reconsideration, appeal level 2                        | **CMS-20033**                | Filed with the QIC                                                   |
| Enrollment reconsideration, CAP, deactivation rebuttal | **No CMS form**              | MACs publish their own coversheets; the substance is a signed letter |
| Correcting the enrollment record                       | **CMS-855I / 855B / 855R**   | As applicable to the entity and the reassignment                     |
| Business identity theft with the IRS                   | **Form 14039-B**             | Where a Form 1099 was issued against your EIN                        |
| Consumer identity theft                                | **IdentityTheft.gov report** | Only where personal identifiers were exposed                         |

<div className="resource-card">
  <div className="resource-card__glyph">XLSX</div>

  <div className="resource-card__body">
    <p className="resource-card__kicker">Fill-in workbook</p>
    <p className="resource-card__title">Provider identity theft denial packet</p>
    <p className="resource-card__desc">Six sheets: a deadline calculator that takes the date on your notice and tells you what is due when, the declaration itself executed under 28 U.S.C. § 1746, a schedule of disputed claims, an authorized-billers exhibit, and a contact log. Fill in the shaded cells.</p>
    <p className="resource-card__meta"><span>Excel / Google Sheets</span><span>6 sheets</span><span>Updated August 2026</span></p>
    <a className="resource-card__cta" href="/download/provider-identity-theft-denial-packet.xlsx" download>Download the workbook</a>
  </div>
</div>

Open it in Google Sheets or Excel and complete the **deadline calculator** first. Some response windows are only 15 days and run while the investigation is still underway.

It is a template, not a filing. Counsel should review and transmit it.

## Steps

<Steps>
  <Step title="Fix the date you learned, and preserve everything">
    Before anything else, record the date and the source. That date anchors every later argument about your diligence, and it is the first thing an investigator, a payer, and a plaintiff will ask for.

    Preserve the notice, envelope, caller's account, and system alert. Capture the current NPPES or PECOS record before making a correction because the unauthorized change is evidence.
  </Step>

  <Step title="Do not deactivate the NPI reflexively">
    <Warning>
      **Deactivation is usually the wrong first move, and it is frequently the advice you will be given.**

      Deactivation does not erase previously submitted fraudulent claims or an overpayment demand. It may interrupt legitimate claims, active payer enrollments, and pending preauthorizations across every entity that bills under the dentist's NPI. A new number can also require rebuilding the credentialing chain.

      The NPI is designed to be permanent; a deactivated NPI is never reassigned to anyone else. Deactivation and reissuance is a real remedy in a genuine, unrecoverable compromise, but it is an endgame decision made with counsel and your MAC, not a reflex on day one. What you *should* do immediately is lock the accounts: change NPPES, PECOS, and I\&A credentials, confirm multi-factor authentication is on, and review authorized surrogates and delegated users.
    </Warning>
  </Step>

  <Step title="Establish what is actually yours">
    Define the claim scope before issuing a denial. For each claim or date range, review the dentist's schedule, PMS, license status, location, and every legitimate billing entity in the group. Include medical claims properly billed for dental-related work, such as sleep appliances or oral surgery. See [Bill medical for dental work](/guides/billing/bill-medical-for-dental-work).

    Three buckets come out of this: **not ours**, **ours and correct**, and **ours and wrong**. You will very likely have some of the third.

    **If part of it turns out to be yours and wrong, that is an overpayment on its own clock.** The report-and-return obligation under 42 U.S.C. § 1320a-7k(d) applies to that portion regardless of what happened to the rest, and the identity theft does not toll it. Split the tracks and run both. See [Report and return overpayments](/guides/compliance/report-and-return-overpayments).
  </Step>

  <Step title="Write the denial statement">
    This is the deliverable. See [What the denial statement must contain](#what-the-denial-statement-must-contain) below for the substance; it is the artifact that every subsequent step attaches.

    Draft it with counsel. It goes to a federal program, it will be relied on, and a materially false statement in it is itself a federal offense under 18 U.S.C. § 1035.
  </Step>

  <Step title="Contact the UPIC through the Victimized Provider Project">
    CMS runs a **Victimized Provider Project** for exactly this situation, acknowledging that providers whose Medicare identities are stolen are "victimized twice", once by the theft and once by the financial consequences.<sup>1</sup>

    The route is your **Unified Program Integrity Contractor** (UPIC), the CMS fraud investigator for your region. Report the suspicious activity, submit the denial statement, and respond to the UPIC's inquiries, including interviews, **after verifying the investigator's credentials**.

    <Tip>
      **Ask the assistant which contractor is yours.** There are five UPIC jurisdictions and more than a dozen MAC jurisdictions, and Part A/B and DME are frequently different contractors for the same state. Rather than reproduce assignments here that move between contract cycles, tell the assistant on this site which state your PC is *enrolled* in and it will hand you the current CMS directory entries for both, plus your state's Medicaid Fraud Control Unit and program integrity director.
    </Tip>

    The UPIC investigates and reports its findings to CMS. That finding is what unwinds the overpayment.
  </Step>

  <Step title="Contact the MAC in parallel">
    Your Medicare Administrative Contractor is a different party with different levers: it issued the demand letter, it holds the enrollment record, and it controls recoupment.

    Ask it to confirm whether any recent enrollment changes were made, give it the beneficiary names and dates from any patient reports, and put the denial statement in its file. CMS's own guidance is that beneficiary information "will help them investigate."
  </Step>

  <Step title="Protect the deadlines while the investigation runs">
    The investigation will outlast your appeal windows. Do not wait for it.

    | Action                                              | Deadline                                             | Effect                                                                                                                                                                                                                              |
    | --------------------------------------------------- | ---------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
    | **Rebuttal statement** under 42 C.F.R. § 405.374    | At least **15 days** from the notice                 | Argues that a suspension, offset, or recoupment should not take effect. It is *not* an appeal and does not preserve appeal rights                                                                                                   |
    | **Deactivation rebuttal** under 42 C.F.R. § 424.546 | **15 calendar days** from the notice                 | A different instrument for a different action. A signed, dated letter specifying the facts disputed and the reasons, with all supporting documentation. **One only**, and the decision carries no further rebuttal or appeal rights |
    | **Redetermination** (MAC)                           | **120 days** to file; **30 days** to stop recoupment | Level 1                                                                                                                                                                                                                             |
    | **Reconsideration** (QIC)                           | **180 days** to file; **60 days** to stop recoupment | Level 2, the last level at which recoupment stops                                                                                                                                                                                   |
    | **ALJ hearing** (OMHA)                              | 60 days                                              | Level 3; recoupment proceeds                                                                                                                                                                                                        |
    | **Medicare Appeals Council**                        | 60 days                                              | Level 4                                                                                                                                                                                                                             |
    | **Federal district court**                          | 60 days                                              | Level 5                                                                                                                                                                                                                             |

    File the rebuttal *and* the redetermination. They do different things.
  </Step>

  <Step title="Run the Medicaid track separately">
    Medicaid is not a copy of Medicare here, and the difference is unfavorable. See [The Medicaid track](#the-medicaid-track) below.
  </Step>

  <Step title="Report the theft to law enforcement and HHS OIG">
    CMS explicitly recommends a **police report**. File one; the report number is evidence that the denial was contemporaneous rather than constructed after a demand letter arrived.

    Report to **HHS OIG** through its fraud hotline and online reporting form. If personal identifiers such as an SSN were involved, file with the FTC at IdentityTheft.gov as well.
  </Step>

  <Step title="Clean up the tax and Treasury consequences">
    A fraudulent 1099 reports income to the IRS that the entity never received, and an unpaid overpayment gets referred to the Department of the Treasury for collection.

    Address both records. Ask the MAC to correct or withdraw the 1099 after the UPIC finding, and report business identity theft to the IRS when appropriate. **Form 14039-B** is the business identity-theft affidavit for misuse of an EIN.<sup>4</sup> Coordinate with your CPA rather than reporting income the group did not receive.
  </Step>

  <Step title="Notify the other payers and the licensing board">
    Notify dental payers that credential the same NPI, including relevant Delta Dental companies, national carriers, and Medicaid dental benefit administrators. Use a consistent written statement so they can flag unauthorized claims before a separate credentialing action begins.

    Whether a report to the state licensing board is required or merely advisable depends on the state and on what happened. Ask counsel, but do not let the board learn about it from a payer.
  </Step>

  <Step title="Harden and assign the monitoring">
    Close the hole and give the watching a named owner. See [Verify it worked](#verify-it-worked).
  </Step>
</Steps>

## What the denial statement must contain

The point of the statement is to be **specific enough to be relied on and narrow enough to survive scrutiny**. A vague blanket denial is worth very little; an overbroad one is worse than nothing, because a single claim that turns out to be legitimate discredits the whole document.

Sign it under penalty of perjury. Federal law permits an unsworn declaration in place of a notarized affidavit where it is dated and states, in substance, *"I declare under penalty of perjury that the foregoing is true and correct"*, **28 U.S.C. § 1746**.<sup>3</sup> That form is available anywhere, immediately, and carries the same weight.

**Identify yourself precisely.** Full legal name as enrolled, NPI, state license number(s), the PC's legal name and TIN, and the Medicare and Medicaid enrollment identifiers at issue.

**Scope the denial to specific claims.** List claim-control numbers, dates of service, beneficiary identifiers, billing entity, and items or services. If detailed claim data is unavailable, identify the date range and payer, state the scope of the denial, and request the full claim list.

**Make three separate denials, because they are three different assertions.** That you did not render the services. That you did not order, refer, prescribe, or certify medical necessity for them. That you did not authorize any person or entity to submit claims using your identifiers.

**State affirmatively what is true.** Explain where the dentist practiced on the relevant dates, their actual scope of practice, which entities were authorized to bill under the NPI, and whether any employment, contractual, ownership, or referral relationship existed with the submitting entity. This factual account gives the payer more to verify than a bare denial.

**Attach the evidence.** Schedule or PMS extracts for the dates, the list of authorized billing entities, the police report number, the date and manner in which you learned, and any NPPES or PECOS change records.

**Say what you have already done.** UPIC contact, MAC contact, police report, credential lockdown, OIG report, with dates. This is the diligence record.

**Deny only what you have actually verified, and say so about the rest.** "I did not render or order these services" for claims you have checked, and "I have not yet been able to review claims X through Y and will supplement" for the rest, is a stronger document than a confident denial of everything.

A false statement in connection with the delivery of or payment for health care benefits is a federal crime under **18 U.S.C. § 1035**, carrying up to five years. The statement is a legal instrument, not a letter of complaint. It should be drafted and transmitted by counsel.

## The Medicaid track

Medicaid runs on a different rule and it is harsher, so treat it as its own workstream rather than a cc: on the Medicare one.

**The suspension is mandatory, not discretionary.** Under **42 C.F.R. § 455.23(a)(1)**, the State Medicaid agency **must** suspend all Medicaid payments to a provider once it determines a credible allegation of fraud exists for which an investigation is pending, unless it has good cause not to suspend, or to suspend only in part. Medicare's parallel authority at § 405.371(a)(2) says CMS *may*. That word is the difference between a suspension you can argue against and one the state has to impose first and reconsider later.<sup>2</sup>

The term **"credible allegation of fraud"** does not itself identify who submitted the claims. Under 42 C.F.R. § 455.2, an allegation may come from sources such as hotline tips, claims-data analysis, audit patterns, or law enforcement and must be verified by the state as having indicia of reliability.

**Good cause is the target, and it runs on written evidence.** The exceptions at § 455.23(e) and (f) let the State decline to suspend, lift a suspension, or suspend only in part. One of them turns expressly on the State determining, **based on written evidence**, that the suspension should be removed. Your denial statement, the police report, the UPIC engagement, and the schedule extracts are that written evidence. Assemble them for the state agency in the same package.

**Notice is fast, and can be withheld.** The agency must send notice within **5 days** of suspending, unless law enforcement asks in writing that notice be temporarily withheld. So a suspension may be the first thing you learn, and it may arrive after the investigation has been running for a while.

The **state Medicaid agency's program-integrity unit** handles the payment suspension and good-cause determination. The **Medicaid Fraud Control Unit** investigates and prosecutes. Each of the 50 states, D.C., Puerto Rico, and the Virgin Islands has an MFCU, often within the Attorney General's office, and 42 C.F.R. part 1007 requires separation from the Medicaid agency. Send the factual denial to the appropriate recipients, but have counsel manage contact with the law-enforcement unit.

**A Medicaid suspension can pull Medicare down with it.** Under 42 C.F.R. § 405.371(a)(4), CMS may suspend Medicare payment on the basis that the provider is subject to a Medicaid payment suspension. And under § 455.416, State Medicaid agencies must deny or terminate enrollment for a provider **terminated** under Medicare or another state's Medicaid or CHIP program.

For a multi-state group this is the compounding risk: an adverse action against one dentist in one state can propagate to the federal program and, if it escalates from suspension to termination, to every other state where that dentist is enrolled. See [Why multi-state groups have one PC per state](/concepts/entities/one-pc-per-state).

## If enrollment is revoked

A revocation under 42 C.F.R. § 424.535(a)(8) is generally effective 30 days after CMS mails notice and carries a reenrollment bar of at least one year.

* **Reconsideration** under 42 C.F.R. § 498.22 must be filed within **60 days after receipt** of the initial determination. Receipt is presumed five days after the date on the letter, so MACs administer the period as **65 days from the letter date**. Calendar from the letter date rather than the date it reached the office. This is the route for an identity-theft revocation.
* **A corrective action plan** under 42 C.F.R. § 405.809 is available only for revocations based on noncompliance, and MACs administer its window as 35 days from the letter date. It is not the path here, and pursuing it instead of a reconsideration burns the reconsideration window.
* Beyond reconsideration: ALJ hearing, then Departmental Appeals Board review, then judicial review.

Tell your dental payers and any hospital or surgery center where the dentist holds privileges. Many contracts condition participation on federal program standing, and the discovery is much worse than the disclosure.

## Verify it worked

* [ ] Date and source of discovery recorded
* [ ] Notices, envelopes, and system records preserved
* [ ] NPPES, PECOS, and I\&A credentials rotated; MFA on; surrogates and delegated users reviewed
* [ ] NPI **not** deactivated absent a considered decision with counsel and the MAC
* [ ] Every claim sorted into not-ours / ours-and-correct / ours-and-wrong
* [ ] 60-day clock started on anything in the third bucket
* [ ] Denial statement signed under 28 U.S.C. § 1746, scoped to specific claims
* [ ] UPIC contacted through the Victimized Provider Project; statement submitted
* [ ] MAC contacted; beneficiary names and dates provided; statement in the file
* [ ] Rebuttal filed within the § 405.374 window
* [ ] Redetermination filed by day 30 of the demand letter
* [ ] Medicaid: good-cause package delivered to the state program integrity unit
* [ ] Police report filed; number recorded
* [ ] HHS OIG report filed; FTC report if personal identifiers were exposed
* [ ] 1099 and Treasury referral addressed with the MAC and the CPA
* [ ] Dental payers and Medicaid DBAs notified in writing
* [ ] Licensing board question resolved with counsel
* [ ] A named owner assigned for ongoing NPI monitoring across all entities

## Common failure modes

| Failure                                                                | Consequence                                                             |
| ---------------------------------------------------------------------- | ----------------------------------------------------------------------- |
| Treating a patient's "I never saw that doctor" call as a service issue | The earliest signal is discarded                                        |
| Filing the demand letter to deal with later                            | Recoupment starts day 41; interest from day 31                          |
| Waiting for the UPIC investigation before appealing                    | Appeal windows close during it                                          |
| Filing a rebuttal and assuming it preserved appeal rights              | It doesn't. It is a separate instrument                                 |
| Deactivating the NPI immediately                                       | Legitimate billing across every entity breaks; the overpayment survives |
| A blanket denial covering claims never checked                         | One legitimate claim discredits the whole statement                     |
| Denying the parts that are genuinely your billing errors               | Converts a theft response into a false statement                        |
| Handling Medicaid as a copy of the Medicare response                   | Misses the mandatory suspension and the good-cause window               |
| Enrollment mail going to an unmonitored registered-agent address       | Rebuttal and reconsideration windows expire unseen                      |
| No one assigned to monitor NPIs across the group                       | The second occurrence surfaces the same way as the first                |

## Sources

1. CMS Center for Program Integrity, [Victimized Provider Project](https://www.cms.gov/about-cms/components/cpi/victimizedproviderproject); CMS, [Victimized Provider Project points of contact](https://www.cms.gov/Medicare/Provider-Enrollment-and-Certification/MedicareProviderSupEnroll/downloads/providervictimpocs.pdf) (state-by-state UPIC contact list). Overpayment mechanics, recoupment at day 41, interest from day 31, and the five appeal levels, from CMS, [Medicare Overpayments](https://www.cms.gov/files/document/medicare-overpayments.pdf) (MLN006379, July 2025), and the limitation on recoupment at [42 U.S.C. § 1395ddd(f)(2)](https://www.law.cornell.edu/uscode/text/42/1395ddd). Rebuttal: [42 C.F.R. § 405.374](https://www.law.cornell.edu/cfr/text/42/405.374).
2. Medicaid suspension: [42 C.F.R. § 455.23](https://www.law.cornell.edu/cfr/text/42/455.23); definitions, [42 C.F.R. § 455.2](https://www.law.cornell.edu/cfr/text/42/455.2); Medicare suspension, [42 C.F.R. § 405.371](https://www.law.cornell.edu/cfr/text/42/405.371); Medicaid enrollment termination, [42 C.F.R. § 455.416](https://www.law.cornell.edu/cfr/text/42/455.416); Medicaid Fraud Control Units, [42 C.F.R. part 1007](https://www.ecfr.gov/current/title-42/chapter-V/subchapter-B/part-1007) and HHS OIG, [Medicaid Fraud Control Units](https://oig.hhs.gov/fraud/medicaid-fraud-control-units-mfcu/). CMS, [Medicaid Payment Suspension Toolkit](https://www.cms.gov/medicare-medicaid-coordination/fraud-prevention/fraudabuseforprofs/downloads/medicaid-paymentsuspension-toolkit-0914.pdf).
3. Unsworn declarations under penalty of perjury, [28 U.S.C. § 1746](https://www.law.cornell.edu/uscode/text/28/1746). False statements relating to health care matters, 18 U.S.C. § 1035. Report-and-return obligation, 42 U.S.C. § 1320a-7k(d).
4. Enrollment revocation and appeals: [42 C.F.R. § 424.535](https://www.law.cornell.edu/cfr/text/42/424.535); [42 C.F.R. § 498.22](https://www.law.cornell.edu/cfr/text/42/498.22); [42 C.F.R. § 405.809](https://www.law.cornell.edu/cfr/text/42/405.809); deactivation rebuttals, [42 C.F.R. § 424.546](https://www.law.cornell.edu/cfr/text/42/424.546). For how MACs administer the CAP, reconsideration, and rebuttal windows, see Noridian, [Provider Enrollment Reconsiderations, CAPs, and Rebuttals](https://med.noridianmedicare.com/web/jeb/enrollment/provider-enrollment-appeals-process). Appeal forms: CMS-20027 (redetermination) and [CMS-20033](https://www.cms.gov/medicare/cms-forms/cms-forms/downloads/cms20033.pdf) (reconsideration). Reporting: HHS OIG, [Report Fraud](https://oig.hhs.gov/fraud/report-fraud/); FTC, [IdentityTheft.gov](https://www.identitytheft.gov/). Business identity theft: IRS, [Report Identity Theft for a Business](https://www.irs.gov/newsroom/report-identity-theft-for-a-business) (Form 14039-B). Contractor directories: CMS, [Review Contractor Directory, Interactive Map](https://www.cms.gov/data-research/monitoring-programs/medicare-fee-service-compliance-programs/review-contractor-directory-interactive-map) and [MAC directory](https://www.cms.gov/mac-info).
