NPI fraud: detecting it, reporting it, cleaning the record
Summary
If someone is billing under your NPI, treat it as identity theft with a billing dimension: the claims attach to your record, so speed protects you. Detect it by reconciling your remittances and watching your NPPES record, then report on several tracks — the payer moving the money first, then the OIG, the NPPES enumerator, any state Medicaid program billed, and law enforcement. Finally clean the record: void the fraudulent claims, correct your enrollment, and monitor your exclusion status.
By Gale Editorial · Updated 2026-07-27. Every figure cited to a dated source. How we write.
What NPI misuse looks like — and why it lands on you
Your National Provider Identifier is public — anyone can look it up in the NPPES registry — which makes it a convenient handle for billing fraud. When someone submits claims under your NPI, the payments, diagnoses, and utilization attach to your record, not theirs. That is the danger: even though you did nothing wrong, the pattern reads as your billing, and it can trigger audits, overpayment demands, and, in the worst case, an exclusion action against you.
The worst case is worth naming: the OIG can exclude an individual from federal health programs, and the List of Excluded Individuals and Entities is where that becomes public to every credentialer, so an unaddressed scheme under your number is not merely a billing nuisance 1Ref 1HHS Office of Inspector General (2026).Exclusions Program.That the OIG excludes individuals from federal health programs and that the LEIE is the public check, so a wrongful exclusion from NPI misuse would surface there.. Misuse takes a few forms — a fraudster bills your rendering NPI on claims routed to their own pay-to account, a scheme lists you as the ordering or referring provider on services you never authorized, or a former associate keeps billing under your number after you part ways. The rendering vs billing npi distinction matters here: the identifier that says who performed the service is the one most often hijacked, because it lends a real clinician's legitimacy to a fake claim.
How to detect it
Detect NPI misuse the way you would bank fraud: by reading statements you might otherwise skim. Review your Medicare remittance advice and any Explanation of Benefits for services, dates, or places you do not recognize; check your NPPES record periodically for address, contact, or authorized-official changes you did not make; and watch your PECOS enrollment for reassignments you never signed. A patient asking about a visit that never happened is a late but unmistakable signal.
- Reconcile what you billed against what paid. A payment for a claim you never submitted is the clearest tell.
- Set a standing reminder to check NPPES. Unauthorized changes to your record often precede the fraudulent billing.
- Know your ptan vs npi. A reassignment fraud shows up in Medicare enrollment, where your PTAN links to your NPI, so watch both.
- Watch both numbers if you carry them. If your practice has an organizational NPI, understand npi-1 and npi-2 and how misuse of the second npi can be harder to spot than misuse of your individual number.
Report it: who to notify, and in what order
Report NPI misuse on several tracks at once, because no single agency owns the whole problem. Speed matters most where money is still moving, so start there and work outward. The order that protects you best runs from stopping the payments, to notifying the federal fraud authorities, to documenting the identity theft so every later correction has a paper trail behind it.
- The payer whose money is moving, first. For Medicare, your Medicare Administrative Contractor; for a commercial plan, its provider-integrity or special-investigations unit. Stopping the fraudulent payments is the most time-sensitive step.
- The NPPES enumerator, to lock your record. If your registry record was altered, report it so the changes are reversed and the record is flagged.
- The HHS Office of Inspector General, alongside the payer's fraud unit. Report the scheme to the federal fraud authorities in addition to the payer, so a fraud using your number is on record with the enforcers.
- The state Medicaid program, if Medicaid was billed. Each state runs its own provider portal and integrity unit — California's Department of Health Care Services is one example 2Ref 2California Department of Health Care Services (2026).California Department of Health Care Services.Named example that each state Medicaid program runs its own provider portal and integrity channel, the destination for reporting Medicaid-side NPI misuse in that state. — and you report to the program in the state where your NPI was used, since your state's channel controls.
- Law enforcement and the FTC, for the identity theft itself. A police report and an identity-theft report give you the documentation banks, payers, and the registry will ask for.
Protect your record from the fallout
Reporting stops the bleeding; protecting your record keeps the fraud from following you for years. Fraudulent claims under your NPI inflate your billing profile, which is the outlier pattern that draws a Targeted Probe and Educate review — a payer sampling your claims across up to three rounds — so a probe letter may be the first official sign, and your defense is the documentation showing you never rendered the sampled services 3Ref 3Centers for Medicare & Medicaid Services (2026).Targeted Probe and Educate (TPE).That fraudulent claims inflating a billing profile can draw a Targeted Probe and Educate review, whose sampled-claims defense is the clinician's own documentation.. Keep that evidence together from the first day you suspect misuse.
The graver risk is a wrongful exclusion or debarment built on someone else's fraud. Because the List of Excluded Individuals and Entities is the public check credentialers run, verifying your own status there catches a wrongful listing early, and pairing it with SAM.gov — the federal system that carries exclusions and debarments alongside the LEIE — closes the gap, since a name surfacing on either can cost you every federal-program contract until it is cleared 4Ref 4U.S. General Services Administration (2026).SAM.gov.That SAM.gov is the federal exclusion/debarment system complementing the OIG LEIE, so monitoring one's own status means checking both databases.. Set a recurring check of both, not a one-time one.
Clean the record and correct your enrollment
Cleaning the record means getting each fraudulent claim formally reversed and your identifiers restored — slower than reporting, and worth documenting at every step. Ask each payer to void the fraudulent claims and to note in its system that they were not yours; correct any altered NPPES fields back to accurate values; and confirm your PECOS enrollment reflects only reassignments you actually authorized. Keep copies of every confirmation, because the next auditor will ask for them.
Deactivating the NPI is usually the wrong tool. Npi deactivation is rare, disruptive, and reversible, and because your NPI is permanent and tied to your entire history, retiring it does not shed the fraud — it breaks every legitimate claim in flight and rarely solves the problem. The better path is locking and monitoring the existing number. If a former associate is the source, resolving the reassignment in PECOS and terminating their access does more than abandoning your identifier ever would.
Prevent the next misuse
Preventing recurrence is mostly monitoring plus hygiene, since you cannot make a public identifier private. Set a standing reminder to review your NPPES record and your remittances, treat any NPPES change alert as urgent, and never share your NPI credentials or let a billing vendor operate under them without a business associate agreement and clear boundaries. The clinicians who catch misuse early are the ones who read their statements.
NPI misuse clusters in certain schemes — telehealth enforcement patterns in particular show fraudulent operations recruiting or impersonating clinicians to bill under real numbers — so an unsolicited offer to "use your NPI" for a fee is the red flag it appears to be. A number lent for a fee is a number in a fraud scheme, and the exclusion action lands on the name attached to the claims, not on whoever paid you to borrow it.
Common questions
Run your practice on Gale
The software is free. Gale earns one flat 3.5% all-in per paid transaction — only on transactions that actually pay. No subscription, no setup fee, no network cut.
Start or manage a practice →References
- 1.HHS Office of Inspector General (2026). Exclusions Program. HHS Office of Inspector General (OIG). link ✓That the OIG excludes individuals from federal health programs and that the LEIE is the public check, so a wrongful exclusion from NPI misuse would surface there.
- 2.California Department of Health Care Services (2026). California Department of Health Care Services. California Department of Health Care Services. link ✓Named example that each state Medicaid program runs its own provider portal and integrity channel, the destination for reporting Medicaid-side NPI misuse in that state.
- 3.Centers for Medicare & Medicaid Services (2026). Targeted Probe and Educate (TPE). Centers for Medicare & Medicaid Services (CMS). link ✓That fraudulent claims inflating a billing profile can draw a Targeted Probe and Educate review, whose sampled-claims defense is the clinician's own documentation.
- 4.U.S. General Services Administration (2026). SAM.gov. U.S. General Services Administration. linkThat SAM.gov is the federal exclusion/debarment system complementing the OIG LEIE, so monitoring one's own status means checking both databases.
https://www.gale.care/for-providers/ecm-npi-identity-theft · 4 sources. Competitor details are cited to dated public sources and maintained as they change; figures are estimates, not commitments. Synthetic demonstration.