Skip to main content
When claims appear under a clinician’s NPI that the clinician did not render, order, or authorize, the single action that changes the outcome is a specific, dated, signed statement denying the claims, delivered to the right contractor before the rebuttal and appeal windows close. Everything else in this guide either produces that statement or protects the deadlines it has to meet.

Prerequisites

  • The demand letter, suspension notice, audit letter, or beneficiary report that surfaced it
  • Access to the affected clinician’s schedule, EHR, and credentialing file for the claim dates
  • The PC’s enrollment records for the payers involved
  • Healthcare regulatory counsel engaged before anything is submitted

How this surfaces

Almost never through your own billing system, because the fraudulent claims were never in it. Anything a patient reports goes straight to this process, not into a service-recovery queue. A caller saying “my mother’s Medicare statement shows a catheter order from Dr. Shah and she has never seen Dr. Shah” is the earliest and most actionable signal you will get. Capture the beneficiary’s name, the date of service, and the item billed, CMS specifically asks for exactly that when you contact your MAC.

Is there a form?

Not for the denial itself. CMS runs a Victimized Provider Project for exactly this situation, and it routes you to your UPIC and your MAC, neither of which publishes a form for the statement. The submission is a free-form signed writing, and its quality is entirely yours to control. That is why the format matters, and why we publish one. Forms do exist for the actions that follow it:
XLSX

Fill-in workbook

Provider identity theft denial packet

Six sheets: a deadline calculator that takes the date on your notice and tells you what is due when, the declaration itself executed under 28 U.S.C. § 1746, a schedule of disputed claims, an authorized-billers exhibit, and a contact log. Fill in the shaded cells.

Excel / Google Sheets6 sheetsUpdated August 2026

Download the workbook
Open it in Google Sheets or Excel. The deadline calculator is the sheet to fill in first — some of these windows are 15 days, and they run whether or not the investigation has started. It is a template, not a filing. Counsel should review and transmit it.

Steps

1

Fix the date you learned, and preserve everything

Before anything else, record the date and the source. That date anchors every later argument about your diligence, and it is the first thing an investigator, a payer, and a plaintiff will ask for.Preserve the notice, the envelope, the caller’s account, the system alert. Do not overwrite the NPPES or PECOS record before you have captured its current state — the unauthorized change is evidence.
2

Do not deactivate the NPI reflexively

Deactivation is usually the wrong first move, and it is frequently the advice you will be given.Deactivating stops nothing that already happened — the fraudulent claims are historical and the overpayment demand survives. What it does do is break every legitimate claim in flight across every PC the clinician bills under, invalidate active payer enrollments and prior authorizations, and require the whole credentialing chain to be rebuilt against a new number.The NPI is designed to be permanent; a deactivated NPI is never reassigned to anyone else. Deactivation and reissuance is a real remedy in a genuine, unrecoverable compromise, but it is an endgame decision made with counsel and your MAC, not a reflex on day one. What you should do immediately is lock the accounts: change NPPES, PECOS, and I&A credentials, confirm multi-factor authentication is on, and review authorized surrogates and delegated users.
3

Establish what is actually yours

Before you deny anything, determine precisely which claims you can deny. For each claim or date range at issue, check the clinician’s schedule, the EHR, licensure and location for that date, and whether any legitimate entity in the group could have submitted it.Three buckets come out of this: not ours, ours and correct, and ours and wrong. You will very likely have some of the third.If part of it turns out to be yours and wrong, that is an overpayment on its own clock. The report-and-return obligation under 42 U.S.C. § 1320a-7k(d) applies to that portion regardless of what happened to the rest, and the identity theft does not toll it. Split the tracks and run both. See Report and return overpayments.
4

Write the denial statement

This is the deliverable. See What the denial statement must contain below for the substance; it is the artifact that every subsequent step attaches.Draft it with counsel. It goes to a federal program, it will be relied on, and a materially false statement in it is itself a federal offense under 18 U.S.C. § 1035.
5

Contact the UPIC through the Victimized Provider Project

CMS runs a Victimized Provider Project for exactly this situation, acknowledging that providers whose Medicare identities are stolen are “victimized twice”, once by the theft and once by the financial consequences.1The route is your Unified Program Integrity Contractor (UPIC), the CMS fraud investigator for your region. Report the suspicious activity, submit the denial statement, and respond to the UPIC’s inquiries, including interviews, after verifying the investigator’s credentials.
Ask the assistant which contractor is yours. There are five UPIC jurisdictions and more than a dozen MAC jurisdictions, and Part A/B and DME are frequently different contractors for the same state. Rather than reproduce assignments here that move between contract cycles, tell the assistant on this site which state your PC is enrolled in and it will hand you the current CMS directory entries for both, plus your state’s Medicaid Fraud Control Unit and program integrity director.
The UPIC investigates and reports its findings to CMS. That finding is what unwinds the overpayment.
6

Contact the MAC in parallel

Your Medicare Administrative Contractor is a different party with different levers: it issued the demand letter, it holds the enrollment record, and it controls recoupment.Ask it to confirm whether any recent enrollment changes were made, give it the beneficiary names and dates from any patient reports, and put the denial statement in its file. CMS’s own guidance is that beneficiary information “will help them investigate.”
7

Protect the deadlines while the investigation runs

The investigation will outlast your appeal windows. Do not wait for it.File the rebuttal and the redetermination. They do different things.
8

Run the Medicaid track separately

Medicaid is not a copy of Medicare here, and the difference is unfavorable. See The Medicaid track below.
9

Report the theft to law enforcement and HHS OIG

CMS explicitly recommends a police report. File one; the report number is evidence that the denial was contemporaneous rather than constructed after a demand letter arrived.Report to HHS OIG through its fraud hotline and online reporting form. If personal identifiers such as an SSN were involved, file with the FTC at IdentityTheft.gov as well.
10

Clean up the tax and Treasury consequences

A fraudulent 1099 reports income to the IRS that the entity never received, and an unpaid overpayment gets referred to the Department of the Treasury for collection.Address both: ask the MAC to correct or withdraw the 1099 once the UPIC finding lands, and raise business identity theft with the IRS — Form 14039-B is the business identity theft affidavit for misuse of an EIN.4 Coordinate with your CPA; do not simply report income you never received.
11

Notify the other payers and the licensing board

Commercial payers credential the same NPI and will see the same claims history. Notify them in writing with the same statement, before they discover it through their own program integrity process and open a credentialing action.Whether a report to the state licensing board is required or merely advisable depends on the state and on what happened. Ask counsel, but do not let the board learn about it from a payer.
12

Harden and assign the monitoring

Close the hole and give the watching a named owner. See Verify it worked.

What the denial statement must contain

The point of the statement is to be specific enough to be relied on and narrow enough to survive scrutiny. A vague blanket denial is worth very little; an overbroad one is worse than nothing, because a single claim that turns out to be legitimate discredits the whole document. Sign it under penalty of perjury. Federal law permits an unsworn declaration in place of a notarized affidavit where it is dated and states, in substance, “I declare under penalty of perjury that the foregoing is true and correct”, 28 U.S.C. § 1746.3 That form is available anywhere, immediately, and carries the same weight. Identify yourself precisely. Full legal name as enrolled, NPI, state license number(s), the PC’s legal name and TIN, and the Medicare and Medicaid enrollment identifiers at issue. Scope the denial to specific claims. Claim control numbers, dates of service, beneficiary identifiers, billing entity, and items or services — or, where you have not been given claim detail, the date range and payer, with an express statement that the denial extends to any claim within that scope and a request for the claim list. Make three separate denials, because they are three different assertions. That you did not render the services. That you did not order, refer, prescribe, or certify medical necessity for them. That you did not authorize any person or entity to submit claims using your identifiers. State affirmatively what is true. Where you were practicing on those dates, what you actually practice, which entities are authorized to bill under your NPI, and that you have no relationship — employment, contractual, ownership, or referral — with the entity that submitted the claims. A denial supported by an affirmative account is far stronger than a denial alone. Attach the evidence. Schedule or EHR extracts for the dates, the list of authorized billing entities, the police report number, the date and manner in which you learned, and any NPPES or PECOS change records. Say what you have already done. UPIC contact, MAC contact, police report, credential lockdown, OIG report, with dates. This is the diligence record. Deny only what you have actually verified, and say so about the rest. “I did not render or order these services” for claims you have checked, and “I have not yet been able to review claims X through Y and will supplement” for the rest, is a stronger document than a confident denial of everything. A false statement in connection with the delivery of or payment for health care benefits is a federal crime under 18 U.S.C. § 1035, carrying up to five years. The statement is a legal instrument, not a letter of complaint. It should be drafted and transmitted by counsel.

The Medicaid track

Medicaid runs on a different rule and it is harsher, so treat it as its own workstream rather than a cc: on the Medicare one. The suspension is mandatory, not discretionary. Under 42 C.F.R. § 455.23(a)(1), the State Medicaid agency must suspend all Medicaid payments to a provider once it determines a credible allegation of fraud exists for which an investigation is pending, unless it has good cause not to suspend, or to suspend only in part. Medicare’s parallel authority at § 405.371(a)(2) says CMS may. That word is the difference between a suspension you can argue against and one the state has to impose first and reconsider later.2 “Credible allegation of fraud” is a low bar and says nothing about you. It is defined at 42 C.F.R. § 455.2 as an allegation from any source — hotline tips, claims data mining, audit patterns, law enforcement — verified by the State and bearing indicia of reliability. Nothing in it requires a finding about who actually submitted the claims. Good cause is the target, and it runs on written evidence. The exceptions at § 455.23(e) and (f) let the State decline to suspend, lift a suspension, or suspend only in part. One of them turns expressly on the State determining, based on written evidence, that the suspension should be removed. Your denial statement, the police report, the UPIC engagement, and the schedule extracts are that written evidence. Assemble them for the state agency in the same package. Notice is fast, and can be withheld. The agency must send notice within 5 days of suspending, unless law enforcement asks in writing that notice be temporarily withheld. So a suspension may be the first thing you learn, and it may arrive after the investigation has been running for a while. Two agencies, two purposes. The State Medicaid agency’s program integrity unit controls the suspension and the good-cause determination. The Medicaid Fraud Control Unit — a unit in each of the 50 states, DC, Puerto Rico, and the Virgin Islands, usually within the Attorney General’s office and required by 42 C.F.R. part 1007 to be separate from the Medicaid agency — investigates and prosecutes. You want the denial in front of both, but they will do different things with it, and the MFCU is a law enforcement body. Counsel manages that contact. A Medicaid suspension can pull Medicare down with it. Under 42 C.F.R. § 405.371(a)(4), CMS may suspend Medicare payment on the basis that the provider is subject to a Medicaid payment suspension. And under § 455.416, State Medicaid agencies must deny or terminate enrollment for a provider terminated under Medicare or another state’s Medicaid or CHIP program. For a multi-state group this is the compounding risk: an adverse action against one clinician in one state can propagate to the federal program and, if it escalates from suspension to termination, to every other state where that clinician is enrolled. See Why multi-state groups have one PC per state.

If enrollment is revoked

A revocation under 42 C.F.R. § 424.535(a)(8) is generally effective 30 days after CMS mails notice and carries a reenrollment bar of at least one year.
  • Reconsideration under 42 C.F.R. § 498.22 must be filed within 60 days of receiving the initial determination. Receipt is presumed 5 days after the date on the letter, so MACs administer it as 65 days from the letter date — count from the letter, not from the day it reached you. This is the route for an identity-theft revocation.
  • A corrective action plan under 42 C.F.R. § 405.809 is available only for revocations based on noncompliance, and MACs administer its window as 35 days from the letter date. It is not the path here, and pursuing it instead of a reconsideration burns the reconsideration window.
  • Beyond reconsideration: ALJ hearing, then Departmental Appeals Board review, then judicial review.
Tell your commercial payers and any facility where the clinician holds privileges. Most contracts condition participation on Medicare enrollment, and the discovery is much worse than the disclosure.

Verify it worked

  • Date and source of discovery recorded
  • Notices, envelopes, and system records preserved
  • NPPES, PECOS, and I&A credentials rotated; MFA on; surrogates and delegated users reviewed
  • NPI not deactivated absent a considered decision with counsel and the MAC
  • Every claim sorted into not-ours / ours-and-correct / ours-and-wrong
  • 60-day clock started on anything in the third bucket
  • Denial statement signed under 28 U.S.C. § 1746, scoped to specific claims
  • UPIC contacted through the Victimized Provider Project; statement submitted
  • MAC contacted; beneficiary names and dates provided; statement in the file
  • Rebuttal filed within the § 405.374 window
  • Redetermination filed by day 30 of the demand letter
  • Medicaid: good-cause package delivered to the state program integrity unit
  • Police report filed; number recorded
  • HHS OIG report filed; FTC report if personal identifiers were exposed
  • 1099 and Treasury referral addressed with the MAC and the CPA
  • Commercial payers notified in writing
  • Licensing board question resolved with counsel
  • A named owner assigned for ongoing NPI monitoring across all entities

Common failure modes

Sources

  1. CMS Center for Program Integrity, Victimized Provider Project; CMS, Victimized Provider Project points of contact (state-by-state UPIC contact list). Overpayment mechanics, recoupment at day 41, interest from day 31, and the five appeal levels, from CMS, Medicare Overpayments (MLN006379, July 2025), and the limitation on recoupment at 42 U.S.C. § 1395ddd(f)(2). Rebuttal: 42 C.F.R. § 405.374.
  2. Medicaid suspension: 42 C.F.R. § 455.23; definitions, 42 C.F.R. § 455.2; Medicare suspension, 42 C.F.R. § 405.371; Medicaid enrollment termination, 42 C.F.R. § 455.416; Medicaid Fraud Control Units, 42 C.F.R. part 1007 and HHS OIG, Medicaid Fraud Control Units. CMS, Medicaid Payment Suspension Toolkit.
  3. Unsworn declarations under penalty of perjury, 28 U.S.C. § 1746. False statements relating to health care matters, 18 U.S.C. § 1035. Report-and-return obligation, 42 U.S.C. § 1320a-7k(d).
  4. Enrollment revocation and appeals: 42 C.F.R. § 424.535; 42 C.F.R. § 498.22; 42 C.F.R. § 405.809; deactivation rebuttals, 42 C.F.R. § 424.546. For how MACs administer the CAP, reconsideration, and rebuttal windows, see Noridian, Provider Enrollment Reconsiderations, CAPs, and Rebuttals. Appeal forms: CMS-20027 (redetermination) and CMS-20033 (reconsideration). Reporting: HHS OIG, Report Fraud; FTC, IdentityTheft.gov. Business identity theft: IRS, Report Identity Theft for a Business (Form 14039-B). Contractor directories: CMS, Review Contractor Directory, Interactive Map and MAC directory.