Provider medical identity theft in NEMT: someone billing with your NPI or redirecting your Medicaid payments
Overview
Provider related medical identity theft is someone using your company's public NPI and Medicaid ID to bill, or changing the bank account where your payments go. HHS-OIG found one scheme that targeted at least 22 state Medicaid agencies and diverted $26.5 million from Medicare and Medicaid. Check payment records monthly, turn on multifactor sign-in on payer portals, and confirm every bank change by calling a number already on file.
On this page
What is provider related medical identity theft?
It is the misuse of a provider’s own identifying information to get money from a payer. CMS’s Medicaid integrity fact sheet quotes this definition of medical identity theft: “the appropriation or misuse of a patient’s or [provider’s] unique medical identifying information to obtain or bill public or private payers for fraudulent medical goods or services.” Two versions reach a NEMT company, and they work differently:
- Billing under your identity. Someone uses your public NPI and Medicaid provider ID to bill for rides you never gave.
- Redirecting your payments. Someone poses as your company and asks a payer to change the bank account that your Medicaid payments go to. Your real claims are paid, into the thief’s account.
NEMT fraud prevention covers fraud by operators and riders: phantom trips, padded miles. This page covers the case where the company is the victim, and the thief is a stranger. How to report Medicaid transportation fraud lists the hotlines for the report itself.
How do thieves use a NEMT company’s NPI and Medicaid ID?
They use numbers that were never meant to be secret. CMS lists public access to National Provider Identifiers and license numbers as one structural risk for honest providers. A covered provider must give its NPI to any entity that needs it to identify the provider in a standard transaction (45 CFR 162.410(a)(3)), so the number travels widely. What protects you is control over what the number can do: who has portal logins, who can change enrollment details, and where payments land.
CMS’s fact sheet says the more parties have access to a provider’s identifiers, the greater the risk, and its examples of high-risk exposure include reassigning identifiers for billing and giving them to staff. It adds that providers who knowingly allow misuse, for example by signing blank forms, can face civil monetary penalties, fines, prison and exclusion from Medicare and Medicaid, even without other fraud. It also says that anyone without proper authority who knowingly and willfully buys, sells or distributes a provider’s identification number under Medicare, Medicaid or CHIP faces, under Social Security Act 1128B(b), up to 10 years in prison, a $500,000 fine for an individual or $1,000,000 for a corporation, or both. In a NEMT company, the first place to look is a billing company or former employee that still holds a login or the company’s identifiers.
How does payment diversion work?
A thief sends a payer a forged request to change a provider’s bank account, and some payers approve it. HHS-OIG described the pattern in a March 2025 report. From 2020 to 2022, people posing as representatives of hospital providers sent fraudulent electronic funds transfer authorization requests to at least 4 Medicare contractors and 22 state Medicaid agencies. Some agencies updated the bank details to the accounts on the requests, and claims payments intended for the providers went to the fraudsters.
OIG’s own investigations put numbers on it. Across those cases about $26.5 million was diverted from Medicare and Medicaid, about $9 million was lost or unrecovered, 23 people were charged and 14 were sentenced. One state Medicaid agency told OIG that about half a dozen fraudulent payments totaling about $1 million went out before the problem was fixed.
OIG’s cases involved people posing as hospital providers. The same forged request could be sent in any provider’s name, because Medicaid pays most providers by electronic transfer to a bank account. In March 2025 the Texas Health and Human Services Commission circulated OIG’s alert, noting that state Medicaid agencies and private payers had been targeted. Two findings from OIG’s survey of payers matter to a small company:
- The requests looked real. Payers reported that they often carried the detailed information needed to verify an account. Some thieves also made changes by phone or through a provider portal.
- Multifactor sign-in was rare. Just under one-fifth of state Medicaid agencies reported using it. The most common checks were contacting an authorized person through a confirmed channel and knowledge-based methods such as password-protected portals.
What are the warning signs?
Payments, letters and calls that do not match what you did are the signs. Watch for these:
- Payments that stop while claims show as paid. If the payment record says a claim was paid and the deposit never arrives, check where the money went.
- A bank-change message you did not request. Connecticut’s July 2026 bulletin describes a process in which the payer contacts the provider’s authorized representative to validate the request, and the representative must confirm small test deposits by email within seven days. An unexpected contact or test deposit points to a change request you did not make.
- A confirmation letter that is wrong. Connecticut mails an outcome letter after each EFT change request and asks providers to read it for an error or an unauthorized change.
- Rides on a payment record that you did not run, or calls from riders and facilities about trips you never made. For Medicare, CMS lists patients phoning about billing from a provider who never treated them as a warning sign.
- An overpayment demand for claims you never billed, or a Form 1099 for money you never received. CMS lists both for Medicare. The 1099 guide shows how to match the forms to your deposits.
- Portal activity you cannot explain. In Connecticut’s March 2026 breach, a thief logged in with stolen employee credentials, reached a provider’s payment accounts on the state portal and downloaded files. An unfamiliar login, a new user or a password reset you did not ask for is the early sign.
Who should you call first?
Call the payer that sends the money, then report the crime. Work down this list the same day.
- The payer. For fee-for-service Medicaid that is the state Medicaid agency’s provider services line, and for managed rides it is each broker that pays you. Ask them to freeze changes on your account and tell you what was submitted and from where. Connecticut’s bulletin gives its Provider Assistance Center, 1-800-842-8440, for any discrepancy in an EFT change.
- The police. CMS’s fact sheet lists local law enforcement and says to notify the credit reporting companies as well.
- Your state Medicaid Fraud Control Unit or the state Medicaid agency. CMS’s fact sheet names both. The Medicaid Fraud Control Unit entry explains what the unit does.
- The HHS-OIG hotline, 1-800-HHS-TIPS (1-800-447-8477), and the Federal Trade Commission, which the CMS fact sheet also names.
- Your NPPES record. Check that the information in it is correct. A covered provider must report a change to its NPI record within 30 days (45 CFR 162.410(a)(4)). The NPI guide shows how to log in.
Keep dated copies of what you receive and send. If claims you never billed lead to a demand for repayment, Medicaid recoupment explains how to contest it.
What controls stop it?
Five habits close most of the paths, and none needs special software.
- Turn on multifactor sign-in everywhere a payer offers it. Connecticut introduced it for portal users on June 2, 2026 and made it mandatory on August 1, 2026, including for changes to EFT information, with a choice of an authenticator app or email verification. Its notices do not link the change to the March and June incidents. Set it for every user, including the owner.
- One login for each person, removed the day they leave. Connecticut’s March 2026 incident began with compromised employee credentials. A billing company’s login is a person’s login too: list it, and cancel it when the contract ends.
- Keep the authorized representative current on every payer’s file. Connecticut’s July 2026 bulletin says the verification goes to the representative on the provider’s most recent enrollment or re-enrollment application. If that is a former employee or an old billing company, the real owner never hears about a change. Medicaid revalidation is the time to fix it.
- Call back on a number you already have. The Texas message tells payers who receive a high-risk request to confirm the requester’s identity with information on file, not with what came in the request. The same rule works for you when someone calls or emails to confirm a bank change. Internal controls for NEMT billing covers who in the office may sign bank-change forms.
- Read the payment record every month. CMS’s fact sheet lists reviewing remittance notices, limiting third-party use of identifiers, and updating enrollment changes, especially when closing or moving a location or changing banking information. Match each deposit to what the payer says it paid. NEMT remittance advice explains how to read one.
Cybersecurity for NEMT companies covers the email and sign-in side in more depth.
What about misuse of a rider’s Medicaid card?
That is the patient-side version, and it starts at the pickup. CMS’s fact sheet tells providers to warn patients about the dangers of card sharing. A driver who confirms two identifiers, a full name and a date of birth, before the ride can catch a rider who is traveling under someone else’s name, and picked up the wrong patient describes that check. If a company suspects a rider’s Medicaid number is being used without the member’s knowledge, the report goes to the same places as above.
Trip records as proof in HealthRide
HealthRide keeps a record of each ride you run, with GPS-recorded miles, timestamps and the rider’s on-screen signature, and the trip log exports as a spreadsheet or a print-ready PDF. When a payer lists rides you do not recognize, that log is what you compare it against, ride by ride.
Frequently asked questions
- Why is a NEMT company's NPI a target for thieves?
- Because the number is public and every payer accepts it. CMS lists public access to NPIs and license numbers as a structural risk for honest providers, and federal rules require a provider to give its NPI to any entity that needs it in a standard transaction. A thief with the number can try to bill under it, or send a forged request that redirects the payments your real claims earn.
- How do fraudsters redirect Medicaid payments?
- They send the payer a forged request to change the bank account on file. HHS-OIG found that between 2020 and 2022 people posing as hospital providers did this to at least 22 state Medicaid agencies and 4 Medicare contractors. Some agencies updated the bank details, and payments went to the fraudsters. OIG's cases show $26.5 million diverted from Medicare and Medicaid and $9 million lost.
- What are the signs that someone is billing under my NPI?
- Look for payment records that list rides you did not run, calls from riders or facilities about trips you never made, and overpayment demands for claims you never billed. CMS also lists a tax Form 1099 for money you never received. Payments that stop arriving while claims show as paid can mean the bank account was changed.
- Who should I call first if I think my payments were diverted?
- Call the payer that sends the money. That is the state Medicaid agency's provider services line and each broker that pays you, since the payer is the one who can lock the account and correct the change. Then file a police report and report it to the HHS-OIG hotline at 1-800-447-8477 or your state Medicaid Fraud Control Unit. Keep dated records of everything you send.
- Does multifactor sign-in on a Medicaid portal stop payment diversion?
- It blocks one route, a thief logging in with stolen credentials, and some state portals now require it. Connecticut made it mandatory on August 1, 2026. It does not stop a forged paper request or a phone call, so keep the call-back rule too: confirm any bank change by calling a number you already have, not one printed on the request.
- Will Medicaid hold me responsible for claims someone else billed under my NPI?
- The answer comes from your state Medicaid agency, so report in writing as soon as you see the claims and ask how it treats a confirmed identity theft. CMS runs a Victimized Provider Project for Medicare that aims to keep providers whose identities were stolen from being wrongly assigned debts. Its page describes Medicare debts, not Medicaid claims. Dated records and a prompt report help in either program.