As consultants, we’ve helped healthcare organizations respond to federal investigations and recover from costly enforcement actions. Each HHS OIG report offers insight into where others have gone wrong and what to watch for. This post reviews the latest findings and what they mean for compliance leaders.
Table of contents
- Key Themes from the Spring 2025 HHS OIG Report to Congress
- Scope of HHS OIG’s Report to Congress
- Section 1: Public Health
- Section 2: Financial Integrity
- Section 3: Medicare and Medicaid
- Section 4: Beneficiary Safety
- Section 5: Data and Technology Security
- Lessons from OIG Enforcement: Staying Ahead of Healthcare Compliance Risks
Key Themes from the Spring 2025 HHS OIG Report to Congress
The Office of Inspector General of the Department of Health and Human Services (HHS) has released its semiannual report to Congress for the period October 1, 2024, to March 31, 2025. This semiannual report to Congress, released by the acting Inspector General Juliet Hodkins, details the findings and summaries of various types of audits and enforcement actions, protecting taxpayer funds, undertaken by the HHS Office of Inspector General (OIG) during the six-month period covered by the report. The total estimated financial impact? A staggering $16.6 billion!
The OIG reports that its work returns $11 in recoveries for every $1 invested. With that kind of return, it’s clear the agency has every incentive to stay aggressive in uncovering waste, fraud, and abuse.
As consultants, we have long looked at the list of topics under study by the OIG in their Active Workplans. We do this to find areas that the OIG is focusing on that overlap with the services offered by our clients. This report offers a similar opportunity.
Scope of HHS OIG’s Report to Congress
The OIG’s report covers five major subject areas:
- Public Health, covering areas such as drug and medical device safety;
- Financial Integrity, covering areas such as improper payments and fiscal effectiveness;
- Medicare and Medicaid, covering program integrity and health care fraud;
- Beneficiary Safety, covering areas such as abuse and neglect, and
- Data and Technology Security.
The report is only 36 pages (short for a government document), and it also contains an Appendix with links to all of the reports and enforcement actions undertaken by the OIG. So let’s take a look at some of the highlights (or in some cases, lowlights) in each subject area. One thing to keep in mind is the time lag for many studies and enforcement actions related to HHS programs. Studies on many items in this report were started three or four years ago. Nevertheless, it is still instructive to review and understand some of the findings today.
Below, I’ll cover relevant takeaways from each of the five main sections.
Section 1: Public Health
Opioids and Drug and Device Safety were the dominant topics in the section.
- The consulting company McKinsey agreed to pay $650 million to resolve allegations that it advised Purdue Pharma L.P. to submit fraudulent claims.
- The owner of Recovery Connections Centers of America, Inc., was ordered to pay more than $3.5 million in restitution and forfeit $1 million. The clinics were found to have provided little to no therapy to patients while billing for more extensive services. The owner was also sentenced to 98 months in prison!
- Magellan Diagnostics, Inc. was ordered to pay $42 million in fines, forfeiture, and patient compensation payments after it concealed a medical device malfunction that produced inaccurately low lead level test results.
Section 2: Financial Integrity
Improper payments included several cases:
- $190 million to acute care hospitals for outpatient services to hospice patients that should have been covered by the hospice program in which the patient was enrolled.
- $454 million for over-the-counter COVID-19 tests that were ordered in excess of the monthly limit of eight tests per enrollee.
- $35 million for improper payments for urological supplies such as catheters.
Cost-effectiveness cases included some perennial favorites:
- OIG estimates it could save up to $4.2 billion by revising the data source for diagnoses included in health risk assessments (HRA) for patients covered by Medicare Advantage plans. Some diagnoses are not documented in patient medical records, but rather in the records of home visits (HRAs) conducted at patients’ homes. CMS identified $13.6 million in overpayments to Medicare Advantage plans, partly due to in-home HRAs.
- Medicare and Medicaid spending on diabetes and weight loss drugs continues to increase at multiple hundreds of percent over the past several years.
Section 3: Medicare and Medicaid
Program Integrity enforcement and evaluations included:
- Independent Health agreed to pay at least $34.5 million for inflating Medicare Risk Adjustments (see HRAs above!). This was also a False Claims Act case.
- The OIG estimates that 46% of the almost 5900 hospitals in the U.S. did not comply with the Hospital Transparency Rule. And the OIG is not the only organization studying this issue. Patient Rights Advocate.org issues reports on hospitals that fail the CMS Price Validator Tool.
- Fraud investigations included several enforcement actions that included both prison terms and fines. The miscreants included physicians, pharmacies, managed care organizations, and telemarketers.
Section 4: Beneficiary Safety
This category contains enforcement actions against several healthcare providers for abuse and neglect. Cases included: a Medicaid caregiver excluded for causing serious bodily injury to her own daughter, who had cerebral palsy, a nursing home owner excluded after convictions on eight counts of cruelty to the infirm, and a pharmacy owner sentenced to prison after he and some associates carried out a predatory HIV medication scheme.
Section 5: Data and Technology Security
This section includes several evaluations by the OIG of the data systems and security controls of various agencies within HHS programs. It also includes one enforcement action involving a lab technician and his co-conspirators who submitted $7 million in false claims for COVID-19 testing services. The lab tech was also sentenced to 7 years in prison.
Lessons from OIG Enforcement: Staying Ahead of Healthcare Compliance Risks
As noted above, this report offers the opportunity to look at recent issues and reports of the OIG for a similar purpose. We know from experience that CMS and State Medicaid Fraud Control Units are always on high alert. They actively look for mistakes and outright schemes that lead to improper payments or fraudulent claims in government healthcare programs.
Our services include working with clients who need an Independent Review Organization (IRO) after a Corporate Integrity Agreement was imposed. We’ve seen how hospice programs, hospitals, skilled nursing facilities, laboratories, and other providers can run afoul of regulations. Don’t let your organization need our help only after an investigation has begun!
In the meantime, we can all applaud their efforts to conserve taxpayer dollars.
