Introduction
The integrity of the Medicare program is once again under the microscope as federal watchdogs highlight a systemic vulnerability in the oversight of Durable Medical Equipment, Prosthetics, Orthotics, and Supplies (DMEPOS). A recent investigation by the Office of Inspector General (OIG) has exposed significant weaknesses in how Medicare Advantage (MA) organizations and the Centers for Medicare & Medicaid Services (CMS) screen suppliers, particularly those operating outside of established networks.
As Medicare Advantage continues to capture a larger share of the federal healthcare budget, the potential for financial leakage through fraudulent billing practices has become a matter of urgent national concern. The OIG’s findings suggest that a lack of rigorous, standardized screening for out-of-network suppliers is creating an environment ripe for exploitation, threatening the fiscal sustainability of the program and the security of taxpayer funds.
Main Facts: The Scope of the Vulnerability
The core issue identified by the OIG centers on the disparity between the screening protocols applied to traditional Medicare and those utilized by private Medicare Advantage plans. While the traditional Medicare program mandates that all DMEPOS suppliers be formally enrolled in the Medicare system—a process that includes rigorous background checks and credentialing—Medicare Advantage organizations have historically operated under a more permissive framework.
The OIG’s latest report scrutinized six major MA organizations that collectively manage over 21,000 DMEPOS suppliers. The investigation revealed that nearly 8,000 of these entities—roughly 38%—are out-of-network providers. Unlike their in-network counterparts, these suppliers are often not subject to the same strict accreditation or state licensure verification processes.
Because current federal law does not explicitly require MA organizations to mandate that all DMEPOS providers be enrolled in Medicare to service plan members, a significant loophole exists. This allows non-enrolled suppliers to bill MA plans with minimal oversight, essentially bypassing the primary safeguard designed to keep fraudulent actors out of the healthcare supply chain.
Chronology of Oversight and Reform
The fight against DMEPOS fraud is not new, but the focus has shifted as the healthcare landscape has evolved.
- 2015–2017: A previous OIG audit revealed that Medicare had improperly paid suppliers over $34 million for equipment provided during inpatient stays, signaling early warning signs of systemic mismanagement.
- 2020–2021: The Trump administration took aggressive action to curb fraudulent activity, implementing a six-month moratorium on the enrollment of certain categories of DMEPOS suppliers in Medicare. This "time-out" was intended to allow CMS to catch up on its backlog of oversight and investigations.
- 2025: CMS reported a significant milestone, successfully preventing over $1.5 billion in suspected fraudulent billing by medical supply companies, demonstrating both the scale of the threat and the effectiveness of targeted intervention.
- Present Day: The current OIG report serves as a critical follow-up, shifting the focus from traditional Medicare to the increasingly complex and often opaque billing practices within Medicare Advantage.
Supporting Data: The High Cost of Lax Screening
The economic implications of these gaps in oversight are staggering. The OIG investigation uncovered a dramatic discrepancy in billing patterns between enrolled and non-enrolled suppliers.

Data from the report shows that the average monthly billing for orthotic supplies among Medicare-enrolled suppliers is approximately $210. In stark contrast, out-of-network suppliers—who are not subject to the same level of scrutiny—bill an average of $1,399 per month for the same items. This is a seven-fold increase, a statistical anomaly that federal auditors point to as a "red flag" for potential illicit activity.
Furthermore, two of the MA organizations interviewed by the OIG explicitly stated that out-of-network providers are responsible for "nearly all" of the fraud schemes identified within their plans. These suppliers often engage in "upcoding" or billing for equipment that was never ordered, never delivered, or deemed medically unnecessary. As MA costs now exceed those of traditional Medicare, the cumulative impact of these fraudulent claims represents a growing threat to the solvency of the Medicare Trust Fund.
The Role of CMS and the Preclusion List
The OIG report did not place the burden of responsibility solely on the shoulders of private MA plans; it also directed significant criticism toward CMS. The agency is accused of failing to leverage its existing tools, specifically the "preclusion list."
The preclusion list is a sophisticated screening mechanism designed to identify and bar suppliers who have previously had their Medicare enrollment revoked or who have engaged in documented fraudulent behavior. According to the OIG, CMS has been utilizing this list in a reactive rather than proactive manner. Instead of preventing fraud by checking the list before payments are authorized, the agency has largely used it to stop suppliers after damage has already been done and taxpayer money has already been dispersed.
By failing to integrate the preclusion list into the routine front-end vetting process for all DMEPOS claims, CMS is inadvertently allowing "bad actors" to jump from one plan to another, exploiting the lack of coordination between Medicare Advantage administrators and federal regulators.
Implications for the Future of Healthcare Administration
The implications of this investigative report are far-reaching, suggesting that a significant overhaul of the relationship between CMS, MA organizations, and medical suppliers is necessary.
1. The Need for Standardized Enrollment
The most prominent recommendation from the OIG is that MA organizations should mandate Medicare enrollment for every DMEPOS supplier they reimburse. By requiring that all suppliers meet the same federal standards as those serving traditional Medicare, the government could close the loophole that allows high-risk, non-enrolled providers to operate in the shadows of the MA system.

2. Enhanced Monitoring of Out-of-Network Providers
MA organizations must be incentivized—or mandated—to increase their oversight of out-of-network providers. This includes not just verifying enrollment, but also performing regular audits of claims for high-cost, high-frequency items like prosthetics and orthotics.
3. Proactive Utilization of Data
The OIG recommends that CMS move toward a more predictive model of oversight. By using the preclusion list as a proactive firewall rather than a retroactive recovery tool, the agency could prevent fraudulent claims from being processed in the first place.
4. Policy and Regulatory Reform
Because current law prevents MA plans from requiring Medicare enrollment for all suppliers, a legislative fix may be required. Policymakers will likely face pressure to draft amendments that grant CMS the authority to set stricter eligibility requirements for any supplier seeking to bill Medicare-funded programs, regardless of whether they are in-network or out-of-network.
Official Responses and Next Steps
In response to the OIG’s findings, CMS has publicly concurred with the recommendations provided in the report. The agency has acknowledged the need for a more robust screening framework and has indicated that it is currently reviewing its internal policies regarding the use of the preclusion list.
"CMS is committed to the integrity of the Medicare program," a spokesperson for the agency noted. "We are currently evaluating the recommendations provided by the OIG and are exploring ways to integrate more comprehensive supplier screening into the Medicare Advantage payment process."
Medicare Advantage organizations are also under increasing pressure to demonstrate that they are acting as responsible stewards of federal funds. Industry experts suggest that the coming months will see a shift in the contractual requirements between MA plans and their supplier networks, with a renewed focus on credentialing and data transparency.
Conclusion
The OIG’s report serves as a stark reminder that as healthcare delivery models shift toward private administration, the complexity of protecting public funds only increases. The current gaps in the screening of DMEPOS suppliers represent a significant vulnerability that, if left unaddressed, will continue to drain millions of dollars from the healthcare system. By moving toward a more unified, rigorous approach to supplier enrollment and leveraging data-driven screening tools like the preclusion list, the federal government and its private partners can ensure that taxpayer dollars are used to provide legitimate care to beneficiaries, rather than lining the pockets of those who exploit the system.
