The Importance of Fraud, Waste, and Abuse Training in Healthcare – The HIPAA Journal

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.
Posted By on Mar 31, 2025
Fraud, waste, and abuse training in healthcare is important to educate workforce members on federal laws and regulations designed to safeguard the integrity of publicly funded health programs. The training should not only cover the laws and regulations, but also how to identify and report violations and the consequences of non-compliance.
The Department of Health and Human Services (HHS) separates its definitions of fraud, waste, and abuse in healthcare to distinguish between activities that intentionally violate federal laws and regulations from activities that violate federal laws and regulations due to a lack of care, inefficiencies, and improper – but not intentionally improper – procedures.
Fraud in healthcare is intentionally submitting information to a health plan or health program that is false (including situations in which the perpetrator should have known the information was false) for personal or financial gain. Examples include falsifying claims, billing for services not provided, or misrepresenting diagnoses to justify unnecessary treatments.
Waste in healthcare lacks the intent to deceive but involves the inefficient or unnecessary use of resources. Waste can be due to poor planning, over-ordering, or redundant medical testing that provides little to no benefit. Examples of waste in healthcare include ordering excessive diagnostic scans and stockpiling medications that expire before they can be used.
Abuse in healthcare can – but doesn’t necessarily – involve fraudulent intent. Usually it entails practices that are inconsistent with sound medical or business standards that result in excess costs. Examples include upcoding (charging for a more expensive service than was provided) or performing procedures that exceed those considered clinically appropriate.

The HIPAA Journal

HIPAA Training

That Lowers Breach Risk

Our training goes beyond basic rule coverage by targeting the mistakes that drive most incidents, using real-world, relatable examples drawn from over 10 years of our HIPAA breach reporting.

The Gold Standard in HIPAA Training

by The HIPAA Journal Team

HIPAA Training for Individuals

The HIPAA Journal

HIPAA Training That Lowers Breach Risk

Our training goes beyond basic rule coverage by targeting the mistakes that drive most incidents, using real-world, relatable examples drawn from over 10 years of our HIPAA breach reporting.

The Gold Standard in HIPAA Training by The HIPAA Journal Team

Lessons Cover Emerging Issues Like AI Tools | CEUs & Certificate | Completion Tracking | HIPAA Training for Individuals


HIPAA Training
That Lowers Breach Risk
Our training goes beyond basic rule coverage by targeting the mistakes that drive most incidents, using real-world, relatable examples drawn from over 10 years of our HIPAA breach reporting.
The Gold Standard in HIPAA Training
by The HIPAA Journal Team
HIPAA Training for Individuals
HIPAA Training That Lowers Breach Risk
Our training goes beyond basic rule coverage by targeting the mistakes that drive most incidents, using real-world, relatable examples drawn from over 10 years of our HIPAA breach reporting.
The Gold Standard in HIPAA Training by The HIPAA Journal Team
Lessons Cover Emerging Issues Like AI Tools | CEUs & Certificate | Completion Tracking | HIPAA Training for Individuals
Nobody knows the true scale of fraud, waste, and abuse in healthcare. Current dollar estimates range from 3% to 7% of total healthcare expenditure, which imply that in 2023 between $147 billion and $343 billion was lost to healthcare fraud, waste, and abuse. However, healthcare fraud is not a victimless crime. The losses are recovered through higher premiums for health plan members and employers, and higher federal taxes.
In addition, the consequences of healthcare fraud, waste, and abuse are not only financial. Patients can be the victims of deliberate misdiagnoses and unnecessary medical treatments. Inappropriate prescribing and care inequalities are also consequences. Significantly, trust in healthcare organizations can be eroded by the actions of just one individual, and this can impact patient compliance – potentially resulting in worse patient outcomes.
Patients can also be the perpetrators of healthcare fraud, waste, and abuse – either by allowing somebody else to use their identity to obtain healthcare services, or by obtaining prescription medication and illegally selling it. In a 2013 survey, 30% of medical identity theft victims said the theft occurred due to sharing insurance information with family members or friends, while more than ten thousand people die each year due to the misuse of prescription opioids.
Source: National Institute on Drug Abuse
Fraud, waste, and abuse training should consist of an overview of the federal laws and regulations that safeguard the integrity of publicly funded health programs, how to identify fraud, waste, and abuse in healthcare, and how to report it. Fraud, waste, and abuse training should also cover the consequences to members of the workforce of non-compliance.
The following laws and regulations have been enacted to protect publicly funded health programs from healthcare fraud, waste, and abuse (FWA) and are enforced by HHS’ Office of Inspector General (OIG). However, they can also be used to pursue criminal and civil actions on behalf of private health plans by the FBI, FTC, or coalitions of public and private agencies.
The False Claims Act allows the government to recover damages and penalties from suppliers that knowingly submit, or knowingly cause to be submitted, false or fraudulent claims. The Act protects the government from being overcharged, mischarged, or sold shoddy goods or services. Knowingly retaining an overpayment may also give rise to liability under the Act.
It is important to highlight during fraud, waste, and abuse training that the False Claims Act defines “knowingly” to include not only actual knowledge of a false claim, but acts in deliberate ignorance or reckless disregard of an unlawful activity (i.e., “should have known”). Consequently, healthcare organizations can be held liable for a false claim if they are considered directly or indirectly complicit in a workforce member’s unlawful activities.
The Civil Monetary Penalty Law is similar to the False Claims Act inasmuch as it permits HHS’ OIG to bring criminal cases in the event of a false claim. However, it also permits HHS’ OIG to bring civil cases before an administrative judge when an individual or organization has engaged in fraud or other improper conduct in order to obtain HHS grants, contracts or other agreements.
The law can also be used by HHS’ OIG to combat waste and abuse if incorrect claims are submitted to publicly funded health programs due to a lack of care or improper procedures. For example, if an organization fails to report drug pricing information accurately, HHS’ OIG can impose a corrective action plan, a financial penalty, or – in the case of repeat offenders – exclusion from public health programs.
The Anti‐Kickback Statute is a criminal law that prohibits the knowing and willful exchange, offer to exchange, solicitation, or receipt of anything of value in an effort to influence, induce, or reward the referral of federal healthcare program business. No payment (including in kind) is necessary to violate the Statute. Simply offering a kickback is sufficient to activate liability for a criminal violation.
Importantly in the context of fraud, waste, and abuse training, the Statute applies to both the individual offering (or paying) a kickback and the recipient. For example, if a diagnostic lab offers a physician $100 for each Medicare referral – and the physician accepts the kickback – both parties are in violation of the Anti-Kickback Statute. If a referral results in a claim for payment from Medicare, both parties are also liable under the False Claims Act.
Stark’s Law prohibits physicians from referring Medicare and Medicaid patients for “designated health services” to entities with whom the physician or an immediate family member has a financial relationship. For example, under Stark’s Law, a general physician is prohibited from referring a patient to a physical therapy office owned by his wife.
Additionally, all entities are prohibited from presenting – or causing to be presented – claims to Medicare or Medicaid for referred services that violate Stark’s Law. There are multiple exceptions to this law when certain conditions are met, and the referral is in the patient’s best interests. For example, self-referrals and referrals to family members are often permitted in rural areas when no other treatment options exist.
The processes for identifying and reporting violations can vary depending on whether a violation occurs internally (workplace colleague, administrator, etc.) or externally (supplier, patient, etc.). Each organization needs to ensure that all workforce members are told how to identify and report each type of violation during fraud, waste, and abuse training in order to mitigate the impact of unlawful activities.
To guide organizations on what information should be provided during fraud, waste, and abuse training, HHS has produced a list of internal “red flags” workforce members should look out for. When identified, these should be reported to the organization’s Security Officer – or can be reported directly to HHS OIG, where the opportunity exists to report violations of healthcare fraud laws anonymously.
The Importance of Fraud, Waste, and Abuse Training in Healthcare The HIPAA Journal
Issues with documentation include:
Changes in attitudes or performance include:
Financial red flags include:
With regards to reporting external violations by suppliers, it can be beneficial to explain the “qui tam” process during fraud, waste, and abuse training – especially if an organization runs a program that supports qui tam whistleblowers. Preventing external violations by patients can be resolved by implementing identification processes beyond those recommended by the Joint Commission – for example, at least one form of photo ID.

The HIPAA Journal

HIPAA Training

That Lowers Breach Risk

Our training goes beyond basic rule coverage by targeting the mistakes that drive most incidents, using real-world, relatable examples drawn from over 10 years of our HIPAA breach reporting.

The Gold Standard in HIPAA Training

by The HIPAA Journal Team

HIPAA Training for Individuals

The HIPAA Journal

HIPAA Training That Lowers Breach Risk

Our training goes beyond basic rule coverage by targeting the mistakes that drive most incidents, using real-world, relatable examples drawn from over 10 years of our HIPAA breach reporting.

The Gold Standard in HIPAA Training by The HIPAA Journal Team

Lessons Cover Emerging Issues Like AI Tools | CEUs & Certificate | Completion Tracking | HIPAA Training for Individuals


HIPAA Training
That Lowers Breach Risk
Our training goes beyond basic rule coverage by targeting the mistakes that drive most incidents, using real-world, relatable examples drawn from over 10 years of our HIPAA breach reporting.
The Gold Standard in HIPAA Training
by The HIPAA Journal Team
HIPAA Training for Individuals
HIPAA Training That Lowers Breach Risk
Our training goes beyond basic rule coverage by targeting the mistakes that drive most incidents, using real-world, relatable examples drawn from over 10 years of our HIPAA breach reporting.
The Gold Standard in HIPAA Training by The HIPAA Journal Team
Lessons Cover Emerging Issues Like AI Tools | CEUs & Certificate | Completion Tracking | HIPAA Training for Individuals
In addition to the consequences of non-compliance discussed above (“Healthcare Fraud is Not a Victimless Crime”), it should be explained to workforce members during fraud, waste, and abuse training how the consequences of non-compliance can affect them personally. This is because, unlike penalties for HIPAA violations which are applied to an organization, penalties for violations of healthcare FWA laws and regulations can be applied to individuals.
For example, civil financial penalties per False Claims Act violation range between $13,946 to $27,984 (as of February 2024) plus – if a false claim is paid before the fraud is identified – three time the amount(s) claimed. Criminal financial penalties for violations of the False Claims Act can go up to $250,000 for individuals or $500,000 for organizations. In addition, individuals convicted of a felony violation can face up to five years imprisonment per violation.
HHS’ OIG also has the authority to exclude individuals and organizations from participating in publicly funded healthcare programs. Individuals convicted on a felony healthcare fraud charge are automatically added to the OIG’s Exclusion List, and this means they cannot be employed by, or provide goods or services to, a healthcare provider that participates in a publicly funded healthcare program. In most cases, a healthcare professional will also lose their license to practice.
Most healthcare providers that participate in publicly funded healthcare programs are required to provide fraud, waste, and abuse training to all members of the workforce (including senior management and governing body members). Training must be provided on appointment and at least annually thereafter (see 42 CFR §422.503(b)). The HIPAA Journal is the leading provider of FWA training, HIPAA training, and OSHA training in the healthcare sector.
While basic fraud, waste, and abuse training must be provided to all members of the workforce, additional specialized or refresher fraud, waste, and abuse training may be required when a workforce member’s job function or the business setting is particularly exposed to risks of fraud, waste, or abuse. It is up to each organization’s compliance officer to determine where the risks exist and what type(s) of fraud, waste, and abuse training is required.
Healthcare providers and first tier, downstream, or related entities that are not required by regulation to provide fraud, waste, and abuse training are advised to conduct a risk analysis to identify any areas of their operations that may be exposed to FWA violations. If the analysis identifies risks, threats, or vulnerabilities, organizations should speak with a healthcare compliance professional to seek assistance with developing a healthcare compliance program.

The HIPAA Journal

HIPAA Training

That Lowers Breach Risk

Our training goes beyond basic rule coverage by targeting the mistakes that drive most incidents, using real-world, relatable examples drawn from over 10 years of our HIPAA breach reporting.

The Gold Standard in HIPAA Training

by The HIPAA Journal Team

HIPAA Training for Individuals

The HIPAA Journal

HIPAA Training That Lowers Breach Risk

Our training goes beyond basic rule coverage by targeting the mistakes that drive most incidents, using real-world, relatable examples drawn from over 10 years of our HIPAA breach reporting.

The Gold Standard in HIPAA Training by The HIPAA Journal Team

Lessons Cover Emerging Issues Like AI Tools | CEUs & Certificate | Completion Tracking | HIPAA Training for Individuals


HIPAA Training
That Lowers Breach Risk
Our training goes beyond basic rule coverage by targeting the mistakes that drive most incidents, using real-world, relatable examples drawn from over 10 years of our HIPAA breach reporting.
The Gold Standard in HIPAA Training
by The HIPAA Journal Team
HIPAA Training for Individuals
HIPAA Training That Lowers Breach Risk
Our training goes beyond basic rule coverage by targeting the mistakes that drive most incidents, using real-world, relatable examples drawn from over 10 years of our HIPAA breach reporting.
The Gold Standard in HIPAA Training by The HIPAA Journal Team
Lessons Cover Emerging Issues Like AI Tools | CEUs & Certificate | Completion Tracking | HIPAA Training for Individuals
Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com
HIPAA Training
That Lowers Breach Risk
Our HIPAA training goes beyond basic rule coverage by targeting the mistakes that drive most incidents, using real-world, relatable examples drawn from over ten years of our HIPAA breach reporting.
The Gold Standard in HIPAA Training
by The HIPAA Journal Team
CEUs & Certificates | Completion Tracking
View HIPAA Training for Individuals
The HIPAA Journal is the leading source of information on the Health Insurance Portability and Accountability Act (HIPAA), providing the best-available HIPAA Training and news coverage of regulatory developments, enforcement actions, data breaches, and best practices for compliance. The HIPAA Journal’s HIPAA training is produced by a team of HIPAA experts, each with over a decade of expertise, who are deeply committed to high-quality HIPAA education.
Subscribe To Weekly
News Digest
HIPAA News
Regulatory Changes
Breach News
HITECH News
HIPAA Advice
Unsubscribe Anytime
Get The FREE
HIPAA Compliance Checklist
Immediate Delivery of Checklist Link To Your Email Address
Get The FREE
HIPAA Compliance Checklist
Immediate Delivery of Checklist Link To Your Email Address
The Administrative Requirements of the Privacy Rule (§164.530) requires covered entities to train all members of their workforces on the policies and procedures developed to comply with the Privacy and Breach Notification Rules. Naturally, the sooner training is provided, the less chance there is of an inadvertent impermissible disclosure due to a lack of knowledge. It is important to note that training must be provided even if a new member of the workforce has held a similar role in a previous position and that some states have mandatory time frames within which training must be provided (for example, in Texas, training must be provided within 90 days).
It is necessary to prove the breach notification requirements are complied with to ensure covered entities and business associates do not overlook notifying individuals in the required timeframe when submitting an annual breach report to HHS’ Office for Civil Rights for breaches affecting fewer than 500 individuals. Some organizations have delayed notifying individuals about data breaches, increasing the risk of individuals’ data being used to commit identity theft or fraud before individuals have the opportunity to protect themselves from such events. The burden of proof standard mitigates the likelihood of individuals being overlooked.
While many types of impermissible uses and disclosures, data thefts, and unauthorized access events are clearly notifiable breaches, there are also many types that are not. If it can be determined that an impermissible use or disclosure does not qualify as a notifiable breach by using the exclusion criteria in §164.402, it will not be necessary to comply with the breach notification requirements – saving organizations time and money, and a potential compliance review by HHS’ Office for Civil Rights.
Although it is not a requirement of HIPAA to provide an anonymous reporting channel, members of the workforce should be encouraged to speak out when they believe a violation of HIPAA has occurred in order that the incident can be investigated and corrected if necessary. It is felt (although cannot not proven) that anonymous reporting channels generate more reports because members of the workforce feel protected against retaliation. However, if an anonymous reporting channel is provided, it needs to be used in compliance with HIPAA, and any PHI contained within the anonymous report has to be safeguarded against unauthorized access, loss, and theft.
It is necessary to monitor business associate compliance because a covered entity can be held liable for a violation of HIPAA by a business associate if the covered entity “knew, or by exercising reasonable diligence, should have known” of a pattern of activity or practice of the business associate that constituted a material breach or violation of the business associate’s obligations under the HIPAA Business Associate Agreement.
It is important to execute HIPAA-compliant Agreements with business associates because if an Agreement does not comply with the relevant standards it is invalid. If an Agreement is invalid, covered entities are not permitted to disclose PHI to the business associate, and any disclosure of this nature would represent a violation of HIPAA.
It is important to identify partners and vendors that qualify as business associates because when a service is provided for or on behalf of a covered entity that involves the creation, receipt, maintenance, or transmission of PHI, a HIPAA Business Associate Agreement has to be entered into which stipulates the permitted uses and disclosures of PHI by the business associate, both parties’ compliance obligations, and other terms that may apply.
There are many examples of when it may be necessary to retrieve documentation within a specific timeframe to comply with HIPAA. The most common is when an individual requests access to their PHI maintained in a designated record set. Less common examples include when an individual wishes to revoke an authorization or when HHS’ Office for Civil Rights requests documentation to resolve a HIPAA complaint. In most cases, the documentation has to be provided within 30 days.
The application of sanctions is important to ensure members of the workforce do not take compliance shortcuts “to get the job done”, and the shortcuts deteriorate into a culture of non-compliance. The sanctions applied should be relevant to the nature of the violation. For example, a verbal warning and/or refresher training may be appropriate for a minor violation, while repeated or more serious violations should attract harsher sanctions. The application of sanctions must be documented and records stored for at least 6 years, either physically in paper records or with HIPAA compliance software.
It is important for organizations to monitor changes to transaction code systems for two reasons. The first is that using out-of-date transaction codes can result in delays to (for example) authorizations and payments. The second reason is that organizations who persistently use out-of-date transaction codes can be reported to CMS – which has the authority to enforce Part 162 of HIPAA via corrective action plans and financial penalties.
The National Provider Identifier identifies your organization or subparts of your organization in Part 162 transactions. It is important that NPIs are used correctly in (for example) eligibility checks and authorization requests to prevent delays in responses to requests for treatment. It is also important that NPIs are used correctly in claims and billing transactions to make sure payments are received on time.
Automatic logoff capabilities are important to prevent unauthorized users from accessing ePHI when a device is unattended. Additionally, if a device is lost or stolen, the device cannot be used to access ePHI without the login credentials being known and used.
It is important that login credentials and passwords are not shared for systems that contain ePHI because, if multiple users are using the same access credentials, it will be impossible to determine when specific users access ePHI. As well as eliminating the usefulness of audit logs and access reports, if a system has been configured to reject multiple logins using the same credentials, it could result in users being blocked from accessing ePHI when necessary, or the system being corrupted.
The requirements to implement and test a data backup plan, an emergency mode operations plan, and a disaster recovery plan fall within the contingency plan standard of the Security Rule (§164.308). These requirements are designed to ensure the integrity and availability of ePHI in the event of a natural or manmade disaster.
Information access policies should make sure that the right people have access to the right level of ePHI at the right time. This means the policies have to be sufficiently flexible to support changing roles, promotions, and time off due to (for example) a suspension or maternity leave. The policies should also include procedures for terminating access to ePHI when a member of the workforce leaves so the departing individual cannot access the organization’s ePHI remotely.
The requirement to have a security management process is the first standard in the HIPAA Security Rule’s Administrative Safeguards. The process must consist of at least a risk analysis, an actioned remediation plan, a sanctions policy, and procedures to regularly review information system activity. All analyses, remediation plans, sanctions, and reviews must be documented. Documentation must be stored for at least 6 years, either physically on paper on via HIPAA compliance software.
HIPAA Authorization Forms have to comply with §164.508 in order to be valid. If a HIPAA Authorization Form lacks the core elements or required statements, if it is difficult for the individual to understand, or if it is completed incorrectly, the authorization will be invalid and any subsequent use or disclosure of PHI made on the reliance of the authorization will be impermissible. For this reason, members of the workforce responsible for obtaining valid authorizations must be trained on the implementation specifications of this standard. HIPAA Authorization Forms must be stored for a minimum of 6 years.
A HIPAA Notice of Privacy Practices advises patients and plan members of their privacy rights, how the organization can use or disclose PHI, and how an individual can complain if they believe their privacy rights have been violated or their PHI has been used or disclosed impermissibly. Notices must be reviewed and amended as necessary whenever a material change affects either an individual’s rights or how PHI can be used or disclosed. They must then be re-distributed and/or re-displayed in accordance with §164.520.
Members of the workforce must know how to respond to patient access and accounting requests – even if it is to direct the request to the HIPAA Privacy Officer – because the primary reason for complaints to HHS’ Office for Civil Rights in recent years has been the failure to respond in the time allowed with the information requested. At present, the majority of HIPAA enforcement activities focus on non-compliance with the patients’ rights standards of the HIPAA Privacy Rule.
The reason it is necessary to have procedures in place to respond to patients exercising their HIPAA rights is that some rights are susceptible to exploitation. For example, procedures should be in place to verify the identity of patients, review confidentiality requests, and determine if a request is being made to support an abusive, deceptive, or harmful activity.
The minimum necessary standard (§164.502(b) and §164.512(d)) requires that only the minimum necessary information is used or disclosed to achieve the purpose of the use or disclosure. This is to better protect the privacy of individually identifiable health information. However, the standard does not apply in every circumstance, and covered entities that apply the standard too rigidly could encounter communication challenges or, in some cases, be in violation of other HIPAA regulations.
The healthcare sector and healthcare records in particular is often targeted by hackers due to the billing details contained in medical records and ransomware value of the personal information in Protected Health Information. Email is one of the most common attack vectors. It is important healthcare staff know how to identify malicious software and phishing emails because the detection capabilities of security software are often limited to how the software is configured and how frequently it is updated. Even the best security software can allow threats to evade detection and, when this happens, users need to be able to identify the threat and report it so other users do not (for example) open a malicious attachment or interact with a phishing email.
It is important that all members of the workforce receive ongoing security awareness training for two reasons. The first reason – that training is provided to all members of the workforce – is because an attacker can infiltrate a network via a device that does not have access to electronic PHI, and then move laterally through the network until they find a healthcare database to attack. The second reason – that training must be ongoing – is due to the evolving nature of cyberthreats. Members of the workforce must be informed about the latest threats, how to recognize them, and how to report them.
The documentation and record keeping of every HIPAA training session is important for two reasons – so that covered entities can keep up to date with which members of the workforce have received what training in the event of transfers or promotions, and so that covered entities can demonstrate the training has been provided in the event of an OCR compliance investigation. Workforce attestation is also required by some state laws with more stringent privacy protections than HIPAA.
The provision of refresher training when there is a material change to policies and procedures is necessary to ensure all members of the workforce affected by the change are made aware of it. Refresher training only has to be provided to those the change affects; but, if the training relates to a change in HIPAA policies and procedures, the training must be documented and – where required by state law – attested to by those who attend. In addition, it is a best practice to provide annual refresher training to all members of the workforce so that those not directly affected by material changes to policies and procedures are made aware of them.
Although covered entities and business associates have many similar HIPAA compliance obligations, some regulations apply differently to each type of organization depending on the nature of their activities. If you qualify as a covered entity, and you also provide services to other covered entities as a business associate, it will be necessary for you to complete the assessment twice.
Delivered via email so please ensure you enter your email address correctly.
Your Privacy Respected
HIPAA Journal Privacy Policy
Delivered via email so please ensure you enter your email address correctly.
Your Privacy Respected
HIPAA Journal Privacy Policy
Please enter correct email address
Your Privacy Respected
HIPAA Journal Privacy Policy

source

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *