How healthcare providers can understand and mitigate FWA risk
To be prepared for a government inquiry of potential fraud, waste and abuse (FWA) into their healthcare billing practices, providers must consider the government’s perspective regarding oversight and enforcement.
Many healthcare providers believe they could readily explain their billing and charging practices — until a government review requires them to do so. What feels routine internally can look quite different when examined externally, particularly in today’s fraud, waste and abuse (FWA) environment, where attention is increasingly focused on patterns, processes and governance.
Providers may be focused on simply avoiding mistakes. But the government’s idea of FWA risk is rarely about individual claims or mistakes. Instead, it focuses on how practices operate over time and whether the organization’s leaders can clearly explain how those practices work.
Framing FWA risk
Providers’ understanding of FWA risk and how the government assesses it is often obscured by imprecise use of terminology. From an oversight and operational perspective, it is best to think about FWA risk through three distinct but related lenses.
1 Regulation. This perspective refers to the rules: statutes, regulations and sub-regulatory guidance, and payment and participation requirements established by entities such as CMS and state Medicaid agencies.
2 Program integrity and oversight. These are activities for monitoring and testing adherence to rules in practice. They include audits, data analysis, medical review and other efforts of CMS contractors, oversight bodies such as the Office of Inspector General (OIG) and state partners. Government-provider interactions tend to occur in this lane.
3 Enforcement. This level of activity involves the exercise of legal authority to address suspected violations. Enforcement includes civil and criminal actions brought by the Department of Justice (DOJ), administrative actions such as civil monetary penalties or exclusions and cases pursued by state Medicaid Fraud Control Units. These matters are adversarial, fact-intensive and consequential.
Understanding these distinctions is important for two reasons:
- They help avoid conflating routine oversight with allegations of wrongdoing. Not every audit or data request signals an enforcement action.
- They clarify how matters evolve, where issues often are first identified through oversight via data analytics or retrospective review of patterns over time and their escalation depends largely upon how organizations understand and respond.
Providers need to understand that oversight or enforcement tends to surface revenue cycle risk that has developed over time through documentation practices, charging workflows, coding interpretations and operational decisions, often in response to clinical practice, operational needs, reimbursement demands and regulatory complexities.
These risks usually develop upstream, where day-to-day decisions become normalized across departments or service lines. Documentation templates are carried forward, charging logic is built into systems and long‑standing interpretations are relied upon because “that’s how it’s always been done,” even as regulatory guidance, payer scrutiny or enforcement priorities shift.
Thus, when probing potential FWA, government reviewers examine patterns such as:
- How services are documented
- How decisions are made
- How billing practices operate in practice
- What governance structures are in place to monitor them, including whether policies and procedures are meaningfully followed
Current focus of FWA activity
Government attention to FWA tends to begin with a focus on program integrity and oversight. Reviewers are increasingly using data analytics (including machine-learning and AI-enabled tools), targeted audits and retrospective reviews to identify patterns that warrant further inquiry.
And they expect healthcare organizations to understand and explain how their billing practices function in practice in addition to how those practices comply with applicable requirements.
The focus is on how care is delivered, documented, justified medically and billed in practice.a Formal enforcement actions typically come after sustained oversight activity that involves testing patterns, decision-making and organizational controls rather than assessing isolated claims.
Because healthcare organizations also are incorporating advanced analytics, including AI, into their revenue cycle operations, reviewers also expect these organizations to be able to explain how these tools function, how decisions are made and what controls are in place to ensure appropriate use.
Areas of FWA focus for hospitals and health systems
For hospitals and health systems, reviewers consistently focus on the following areas:
- Charge capture accuracy, including whether services, supplies and procedures are consistently and appropriately translated from clinical documentation into charges
- Outpatient prospective payment system billing, particularly for clinic visits, observation services and ancillary services
- Modifier usage, such as those related to separate and distinct services, procedural components or billing under special payment rules
- Medical necessity as reflected in the record, especially where services are billed at higher acuity levels or in higher‑cost settings
- Alignment between clinical documentation, charge description masters (CDMs) and billed claims, including whether system logic and operational practices are consistent with billing requirements
In particular, reviewers often focus on whether charging practices are systematically producing results that deviate from the norm and whether organizations have visibility into, and control over, those practices.
Overall, attention tends to be directed at systemic charging and billing practices. Hospitals rarely face FWA exposure because an individual coder made a mistake. Risk usually arises when systems and workflows that are built to operate consistently become misaligned with billing or coverage requirements. These risks are frequently embedded in workflows, electronic systems and charge capture processes.
Areas of attention for physician groups differ from those for hospitals and health systems, as described in the sidebar at the end of this article. In either case, however, when questions arise, organizations are increasingly expected to demonstrate that their billing outcomes are supportable and their underlying processes, decision-making frameworks and controls are well understood and appropriately managed.
How to mitigate FWA risk
Healthcare organizations should prepare to manage FWA risk by proactively assessing their practices internally before they are reviewed externally. For hospitals and health systems, this preparation should be operational and systems-based, with a focus on:
- Regular reviews of facility charging workflows, including how services flow from documentation to charges to claims
- Validation of CDMs against current billing rules and operational reality
- Monitoring of high‑risk outpatient services and modifiers
- Cross‑functional coordination between clinical departments, charging teams, revenue integrity and compliance
In every case, governance is central. Policies and procedures must not only exist but also be understood and followed in practice. Organizations increasingly benefit from using their own data to identify patterns that external reviewers are likely to question.
As the use of data analytics and technology expands, preparation also includes being able
to explain how decisions are made through clinical judgment, operational workflows and technology-enabled processes. Organizations that understand their own systems, and can clearly articulate how those systems function, are best positioned when questions arise.
6 steps for mitigating risk when issues are identified
When potential FWA concerns are identified, an organization’s response can significantly influence how they are resolved. Prompt, thoughtful and appropriately structured responses are more likely to be contained. Those that are handled informally, delayed or poorly documented may draw additional scrutiny.
Mitigating risk begins with clearly understanding the issue and taking the following steps to evaluate it.
1 Conduct structured internal reviews and investigations. Define the scope, timeframe and nature of the issue (including services, providers and processes involved). Well-defined reviews help ensure that findings are accurate and reliable and subsequent actions are appropriately targeted.
2 Identify root cause and operational drivers. Determine whether the issue stems from documentation practices, workflow design, system logic, training gaps or other underlying factors. Surface-level issues corrected without addressing the underlying cause often recur.
3 Assess financial impact and repayment using defensible methodologies. Quantify potential overpayments or financial exposure using approaches that can be clearly explained, supported and replicated, such as through statistically valid sampling, targeted claims analysis or other methods.
4 Implement timely and proportionate corrective actions. Such actions may include focused education, policy or procedure updates, workflow changes and system modifications, each tailored to the nature, scope and root cause of the issue identified.
5 Document actions and decision‑making contemporaneously. Clear records documenting how the issue was identified, evaluated and addressed, including the rationale supporting key decisions, are more credible and defensible than after‑the‑fact explanations.
6 Monitor for sustained effectiveness. Conduct follow‑up reviews to confirm that corrective actions have been implemented as intended and are producing the expected results.
From an oversight and enforcement perspective, these actions are considered collectively as indicators of how an organization governs itself, identifies risk and responds to it, and whether it can sustain corrective action.b
Demonstrating good-faith efforts to identify and remediate issues, supported by clear and timely documentation, can meaningfully influence how a matter is evaluated. Conversely, gaps in documentation, inconsistent responses or delayed action may prompt additional questions, even regarding a minor underlying issue.
When DOJ has contacted you
Contact by the DOJ, the issuance of a subpoena or civil investigative demand or the filing of a qui tam complaint under the False Claims Act marks a clear shift in the government’s posture. Such steps indicate reviewers have identified a theory of potential liability and intend to investigate it through an adversarial process.
The organization also may have been evaluating these issues internally through its operational practices, documentation and controls. With this new development, credibility, documentation and strategic coordination are critical. As a start, the organization should:
- Immediately preserve relevant clinical, charging, billing and operational data
- Align legal, compliance, clinical and revenue cycle teams to ensure facts and messaging are consistent
- Understand the government’s theory, including which services, billing practices and time periods are under scrutiny
- Prepare for data-driven review, including statistical sampling and extrapolation
- Evaluate defensibility based on documentation, controls and good‑faith compliance efforts
Organizations are in the best position if they can clearly articulate their processes, controls and good faith efforts.
Avoiding FWA goes beyond compliance
FWA is often discussed as a matter of compliance — whether requirements are met, documentation is sufficient and billing is technically correct. In practice, it also reflects how an organization understands, governs and manages its operational patterns.
It is these patterns that draw oversight or enforcement attention. And organizations experience them operationally long before they are assessed externally. Assessable patterns include how decisions are made, how processes function over time, and whether organizations have visibility into the process outcomes.
In practice, risk often emerges at the seams, between clinical teams and revenue cycle staff, between automated rules and human judgment or between written policy and how work actually gets done. When organizations do not understand or consistently apply these processes well, risk can develop and proliferate.
An organization’s internal efforts to promote program integrity should not be limited to identifying errors. The organization must be able to explain not only what happened and why, but also how it corrected the error and prevented it from recurring. In that sense, managing FWA risk is not separate from running the organization. It reflects how well the organization is run.
Footnotes
a. HHS OIG, “Work Plan,” page accessed June 8, 2026; and U.S. Department of Justice, “National health care fraud takedown results in 324 defendants charged in connection with over $14.6 billion in alleged fraud,” press release, June 30, 2025.
b. CMS, Medicare Program Integrity Manual, and HHS OIG, Compliance Guidelines, both accessed June 9, 2026.
Areas of FWA focus for physician groups
For physician groups, the attention of fraud, waste and abuse (FWA) oversight and enforcement often centers on professional billing practices and clinical decision-making, particularly where discretion is high and variation across providers can be measured.
Areas of focus include:
- Evaluation and management services, including visit leveling, time‑based billing and consistency between documentation and billed services
- High‑volume or high‑frequency services, especially where utilization appears to exceed peer norms or established benchmarks, with particular emphasis on high-dollar items or services
- Medical necessity, particularly where documentation does not clearly support the intensity, frequency or setting of care
- Incident‑to and supervision requirements, including appropriate billing for services involving advanced practice providers
- Reliance on third‑party billing or management entities, where physicians or group leadership may have limited visibility into how services are coded and billed
In this setting, questions often arise from identifiable patterns at the individual or group level, which are then assessed in the context of documentation, clinical judgment and internal controls.
In their efforts to mitigate FWA risk, physician groups should perform targeted reviews and implement improvements, as necessary, in practice, education and visibility into decision making, especially when it is outsourced.