Downcoded

How a Once-in-a-Lifetime Test Got Billed 520 Times

CMS put its analytics, OIG's exclusion authority and state payment suspensions in the same room in April. Eighty-eight days later it published the scoreboard: 50 providers, $203.3 million, and one lab that billed a once-in-a-lifetime gene test over and over on the same 520 people.


If you run a compliance program, you have spent years guessing at what the government's analytics actually flag. CMS just published an example.

A lab testing provider was billing for once-in-a-lifetime gene testing. Repeatedly.

In 2025 alone it collected $4.5 million for repeat testing on 520 patients, which works out to $8,654 a head in a single year on a test class you order once and never again. Medical record review found falsified records and no medical necessity.

That case sits in a fact sheet CMS published in June for the Medicaid Fraud War Room, the cross-agency operation it stood up on April 23. The provider is not named, the state is not named, and the test code is not given. What CMS did give is the sequence after the flag: OIG issued a notice of intent to exclude, the state stopped sending payments immediately, and investigators kept working the records for recoveries.

Three authorities, one provider, no waiting in line.

What Puts Three Agencies on the Same Flag

The analytics are the least interesting part. Every payer and every contractor in this business runs outlier detection, and CMS has been generating leads it couldn't act on quickly for as long as the program has existed.

What changed in April is the standing table. The Fast Facts sheet lays out the division of labor plainly:

  • The White House Task Force to Eliminate Fraud sets the goals.
  • CMS identifies the highest-risk providers through data analytics and coordinates the room.
  • HHS-OIG investigates, issues the exclusions, and pursues civil monetary penalties.
  • The states bring the payment suspension.

So a single flagged provider gets a federal exclusion track and a state payment-shutoff track running at once, off the same data. Kim Brandt, CMS's deputy administrator and COO, put the design goal in one line:

"Federal and state partners working off the same data, in real time, to stop bad actors before more taxpayer dollars go out the door."

Anyone who has waited on a referral between a MAC, a UPIC and a state Medicaid agency knows how much of the delay is handoff rather than analysis.

What Eighty-Eight Days Bought

CMS published the count on July 28 and pushed it into MLN Connects two days later, which is how it reached the provider channel rather than only the press.

Through 88 days, the War Room drove 42 federal notices of intent to exclude carrying $160.7 million in Medicaid payments since January 1, 2025, and 15 state enforcement actions carrying $46.2 million. Seven providers caught both, so the unique count is 50 providers and $203.3 million.

The two tracks are lopsided, and it matters (chart above). Four in five of those dollars sit behind the federal exclusion notices.

The seven dual-action providers only account for $3.6 million of overlap, which is the residual once you subtract the unique total from the two tracks summed. Most of the money moved through OIG.

Run the averages and you get a program hunting concentration: $4.07 million per identified provider, $3.83 million per federal notice, $3.08 million per state action, across 57 enforcement actions.

Nothing about that shape resembles a broad audit sweep.

The Exclusion Is the Part That Reaches You

Here's the piece that touches organizations nowhere near a War Room flag.

An OIG exclusion under section 1128 of the Social Security Act lands the individual or entity on the List of Excluded Individuals/Entities, and OIG's own guidance is blunt about the downstream liability: anyone who hires an individual or entity on the LEIE may face civil monetary penalties. The remedy OIG names is routine screening of both new hires and current employees, which is a standing chore rather than an onboarding checkbox.

Forty-two notices of intent to exclude in a single quarter, all sourced from one analytics operation, means the LEIE is about to move faster than the screening cadence most organizations set when exclusions trickled in.

Two practical reads for a revenue-cycle or compliance lead:

  • If your LEIE screening runs annually, the cadence was calibrated for a slower list. OIG's guidance says to check routinely, and a miss costs you a civil monetary penalty rather than a denial you can appeal.
  • If you bill anything with a natural frequency ceiling, once-in-a-lifetime gene testing being the obvious one, the utilization pattern in the CMS example is the pattern the model found. Repeat billing of a once-per-lifetime test on the same patients is not a subtle signal.

Final Thoughts

Program integrity operations usually surface as a number in a semiannual report, long after anyone can learn anything from it. This one published a scoreboard at 88 days, named its partners and their roles, and put a worked case on the record with the dollar figure and the patient count attached.

The Medicaid Fraud War Room is the second of these. CMS built the Fraud Defense Operations Center for Medicare in 2025, describes its first-year haul as billions kept from bad actors, and modeled the Medicaid version on it explicitly.

A third would surprise nobody.

For most of the people reading this, the useful part is the description itself: what the government can now see, and how fast three sets of authority move once it sees it. CMS volunteered that, which is more than this industry usually gets.

Thanks for reading.