State MFCUs
A Medicaid Fraud Control Unit is a state law-enforcement unit that investigates and prosecutes Medicaid provider fraud through criminal and civil proceedings. It is usually housed in the state Attorney General’s office.1 Every state except one operates an MFCU. HHS-OIG certifies and oversees the units and maintains the national directory. MFCUs have participated in several significant dental enforcement matters. NAMFCU coordinated the state side of the $$23.9 million Benevis/Kool Smiles resolution, and state units participated in the ImmediaDent/Samson and MB2 matters.2 The DSO enforcement tracker records the allegations, amounts, resolutions, and source documents for each case. An MFCU contact is a fraud investigation by law enforcement, not an audit. Involve counsel before responding. See When to call a lawyer.UPICs also cover Medicaid dental
A Unified Program Integrity Contractor (UPIC) is the CMS contractor that investigates fraud, waste, and abuse across Medicare and Medicaid, including the Medicare-Medicaid data match program. A dental group that bills Medicaid can hear from a UPIC even if it never bills Medicare. Five jurisdictions cover all states and territories, held by three contractors:
Assignments as of August 2026. Look up the UPIC for a specific state on CMS’s Review Contractor Directory, Interactive Map3, and use the state where the PC is enrolled, not where the DSO sits. Published third-party summaries disagree with CMS on several state assignments (Minnesota and Montana are frequently transposed), so defer to the CMS directory, not a cached table.
A UPIC inquiry may involve suspected fraud rather than a routine payment audit, so route it promptly to the appropriate compliance and legal team. If someone used your NPI to submit services you did not render, contact the responsible program-integrity contractor and review CMS’s Victimized Provider Project.4 See Respond to NPI identity theft.
The Medicare contractor ecosystem, in one note. The MAC (claims and enrollment), RAC (contingency-fee overpayment recovery), CERT (error-rate sampling), and SMRC (directed medical review) matter to a dental group only to the extent it bills Medicare; crossover oral surgery, sleep appliances, the “inextricably linked” scenarios. See Medicare and dental. None of them is the UPIC, and none is the MFCU.
DBA and carrier SIU audits
Day to day, the program-integrity contact a dental group actually receives is an audit letter from a payer’s special investigation unit (SIU) or utilization-review team; Medicaid dental benefit administrators (DentaQuest, MCNA, Liberty, and peers) audit on behalf of state programs, and commercial carriers audit their own claims. The usual triggers are statistical outliers: services per visit, procedure mix (surgical-coded extractions, scaling and root planing), radiograph and behavior-management frequency, and same-day code combinations. These are recoupment-driven audits, not fraud investigations, but their findings can be referred upward to the state program-integrity office or MFCU, so respond with the same rigor. The workflow is in Respond to payer audits and Handle recoupments; identified Medicaid overpayments carry the 60-day repayment obligation covered in Report and return overpayments.OIG’s dental oversight record
HHS-OIG’s dental reports and agreements have informed state and federal enforcement work:
CMS’s dental-specific compliance toolkit, Medicaid Compliance for the Dental Professional, catalogs the same risk areas the audits target: unnecessary services, upcoded extractions, behavior-management codes.7
State program-integrity offices publish their own dental work: the Texas HHSC Office of Inspector General’s DSO informational report (May 2017) examined dental service organizations’ role in Texas Medicaid specifically.8
Who is contacting you, and what it means
Sources
- HHS OIG, Medicaid Fraud Control Units, including the unit directory.
- DOJ, Benevis/Kool Smiles settlement (Jan. 10, 2018), coordinated with NAMFCU; USAO W.D. Ky., ImmediaDent/Samson settlement (Nov. 6, 2018); OIG, MB2 CIA. Full case detail in the DSO enforcement tracker.
- CMS, Review Contractor Directory, Interactive Map (jurisdiction assignments).
- CMS, Victimized Provider Project.
- HHS OIG Questionable Billing series: New York, OEI-02-12-00330 (Mar. 2014); Louisiana, OEI-02-14-00120 (Aug. 2014); Indiana, OEI-02-14-00250 (Nov. 2014); California, OEI-02-14-00480 (May 2015).
- HHS OIG, exclusion of CSHM LLC (Apr. 2014).
- CMS, Medicaid Compliance for the Dental Professional.
- Texas HHSC-OIG, DSO informational report (May 31, 2017).