Out-of-network suppliers billed an average of $1,399 a month for orthotics, against $210 from suppliers enrolled in Medicare.
What happened
Medicare Advantage organizations run fewer checks on medical equipment suppliers outside their networks than on those inside them, the HHS Office of Inspector General found in an issue brief published September 14, 2026. The category covers durable medical equipment, prosthetics, orthotics, and supplies, meaning wheelchairs, glucose monitors, braces, and catheters. Medicare Advantage now accounts for more spending than Original Medicare, with roughly 34 million people enrolled. OIG recommended that the Centers for Medicare and Medicaid Services strengthen checks on out-of-network suppliers, make fuller use of its existing fraud prevention list, and require every supplier billing Medicare Advantage to enroll in Medicare, or seek the legal authority to require it. CMS agreed with the recommendations or said it would consider them.
Going deeper
Suppliers inside a plan's network face several required checks, covering state licensing where applicable, review by an accrediting body or against the plan's own standards, and confirmation that the supplier is neither on the CMS Preclusion List nor excluded from federal health programs by OIG. The Preclusion List names providers and suppliers barred from receiving payment from Medicare Advantage plans. Out-of-network suppliers face only the Preclusion List check. Licensing and accreditation are not verified. Current law also prevents Medicare Advantage organizations from requiring that equipment suppliers enrol in Medicare before serving their members, which means CMS never screens many of them at all. Two of the plans OIG interviewed said out-of-network suppliers accounted for nearly all the fraud schemes they encountered, Healthcare Dive reported.
What was said
Fraud involving this equipment "has been a long-standing issue in Medicare, putting millions of taxpayer dollars at risk each year," OIG wrote in the issue brief, noting one recent case in which bad actors are accused of fraudulently billing Medicare more than $10 billion. The office stated that suppliers with the least screening, those billing out of network and not enrolled in Medicare, present the greatest fraud risk to the programme.
In the know
Three things are needed to bill fraudulently for medical equipment, according to a separate OIG white paper published in August: an enrolled supplier, a physician order, and an enrollee's identification number. Fraudsters obtain those numbers through cyberattacks, purchases on criminal marketplaces, social engineering scams, and misuse of the online tools authorized users rely on to look up beneficiary details, OIG found. The paper documents cases where stolen beneficiary information was used to bill for equipment that was unnecessary or never supplied, and raises concerns that lookup systems can be exploited to harvest enrollee data in bulk. Physicians frequently do not learn their names have appeared on fraudulent claims.
The big picture
Government investigators tested how easily that data can be acquired. As part of an audit published in March 2026, GAO staff reviewed dark web marketplaces and made two separate purchases of beneficiaries' personal information, including confidential Medicare beneficiary identifiers, according to the report. GAO also documented CMS suspending payments to 15 providers who allegedly billed more than $4 billion for urinary catheters that were never supplied. For covered entities, the finding that matters is what those identifiers become once they leave the building. A breach exposing Medicare or Medicare Advantage numbers supplies one of the three elements fraud requires, and the harm surfaces as claims against a patient's benefits rather than as new credit accounts. Organizations holding beneficiary numbers should confirm who inside the organization can query lookup tools, whether that access is logged and reviewed, and whether bulk queries would generate an alert.
FAQs
What is the Preclusion List?
A CMS list naming providers and suppliers barred from receiving payment from Medicare Advantage plans and Part D prescription drug plans, usually following a revocation, an exclusion, or conduct CMS judges detrimental to the programme. Plans check it before paying claims.
Why can a Medicare Advantage plan not simply require suppliers to enroll in Medicare?
Current law prevents it, which is why OIG's recommendation asks CMS to seek statutory authority if it cannot act under existing powers. Out-of-network suppliers can serve plan members without ever going through federal enrolment screening.
How would a patient know their Medicare number was used fraudulently?
Through the quarterly Medicare Summary Notice or the plan's explanation of benefits, which list services billed against their coverage. Equipment they never received or orders they never authorized appear there, often months after the claim was paid.
What should a patient do if they find a claim they do not recognize?
Contact the plan or Medicare directly using the number on their card, report it to the HHS OIG hotline, and request a correction. Unlike a payment card, a Medicare number cannot easily be reissued, so monitoring continues afterwards.
Does a breach involving Medicare numbers trigger different obligations?
The notification rules are the same as for any protected health information. What differs is the practical guidance given to affected individuals, since credit monitoring does not detect claims billed against health coverage and benefit statements do.
