Skip to Main Content
Publications

CMS Enrollment Moratoria and the 2026 Fraud and Abuse Enforcement Surge: What Health Care Providers Need to Know Now

Three nationwide Medicare enrollment moratoria have frozen new enrollment for home health agencies, hospices, and certain durable medical equipment suppliers in 2026. A multiagency fraud task force, congressional investigations, and state oversight inquiries are all running in parallel. An August 2026 Office of Inspector General (OIG) white paper on durable medical equipment fraud provides a roadmap for the enforcement tools likely to come next. Health care providers and suppliers, private equity sponsors, investors, and deal parties pursuing acquisitions or de novo projects all need to understand what has changed and act now.

The 2026 Federal Enforcement Landscape

In February 2026, CMS launched the Comprehensive Regulations to Uncover Suspicious Healthcare (CRUSH) initiative, seeking public comment on regulatory changes to strengthen fraud prevention across Medicare, Medicaid, Children's Health Insurance Program (CHIP), and the Health Insurance Marketplace. A proposed CRUSH regulation is expected later in 2026. In March, an Executive Order established a multiagency task force to eliminate fraud. CMS's Fraud Defense Operations Center suspended more than $2.1 billion in potentially fraudulent payments between March 2025 and March 2026, and total Medicare program-integrity savings jumped from $26.3 billion in FY 2024 to $41.9 billion in FY 2025. CMS has sent formal program-integrity inquiries to multiple states – including California, Florida, Maine, Minnesota, and New York – and deferred $259.5 million in federal Medicaid funding to Minnesota, shifting from post-audit disallowances to real-time withholding when fraud is suspected. The House Committee on Energy and Commerce has opened a multistate Medicaid fraud investigation, and states have launched parallel oversight inquiries targeting fraud investigation backlogs and interagency coordination gaps.

Three Nationwide Enrollment Moratoria

Effective February 27, 2026, CMS imposed a six-month nationwide moratorium on new Medicare enrollment for certain durable medical equipment, prosthetics, orthotics, and supplies (DMEPOS) suppliers, building on earlier efforts that identified more than $1.5 billion in suspected fraudulent DMEPOS billing. On May 13, 2026, CMS imposed two separate six-month nationwide moratoria on Medicare enrollment of: (1) new home health agencies, including new branches and practice locations; and (2) new hospices, including new practice locations. Unless lifted or extended, the home health and hospice moratoria run through November 13, 2026.

The moratoria cover all initial enrollment applications, new branches and practice locations, and re-enrollments required under the 36-month rule when a non-exempt change in majority ownership triggers a new enrollment. CMS's proposed CY 2027 provider-enrollment changes would extend this reach to reactivations, providers returning after revocation, and voluntarily terminated providers seeking to reenter Medicare. Routine changes that do not require a new enrollment – such as relocations and updates to provider information – are not blocked but may receive heightened scrutiny. Applications received before the applicable moratorium's effective date are not affected; providers should preserve proof of the receipt date. Once a moratorium lifts, providers that were blocked from enrolling face at least six months of "high" categorical risk screening, which can include onsite review and fingerprint-based criminal-history checks.

The moratoria directly affect health care transactions. Any acquisition or ownership change that triggers the 36-month rule requires a new enrollment that CMS will not accept during the moratorium – parties may need to delay closing, restructure, or plan for a period without Medicare billing privileges. De novo projects lacking an application received before the applicable effective date are paused. Health systems expanding home health or hospice capacity through new branches or entities cannot enroll those locations until the moratoria lift. CMS may assess substance and practical control, and false or misleading enrollment information can result in revocation and reapplication bars of up to ten years.

The August 2026 OIG White Paper on DMEPOS Fraud

In August 2026, the U.S. Department of Health and Human Services (HHS) OIG published "The Nation's Challenge to Combat Durable Medical Equipment Fraud in Medicare" (OEI-02-24-00311). The white paper documents how DMEPOS fraud persists when bad actors obtain access to a Medicare-enrolled supplier, a physician order, and a Medicare enrollee identification number. It recommends stronger enrollment safeguards, physician-order verification, expanded use of analytics and artificial intelligence, more aggressive payment suspensions, protection of Medicare Beneficiary Identifiers, scrutiny of straw owners and unreported ownership changes, and greater oversight of newly enrolled and recently acquired suppliers.

Although the white paper focuses on DMEPOS, its recommendations map closely to vulnerabilities in home health, hospice, and other areas of increased scrutiny. Providers should expect CMS to apply similar tools, including heightened scrutiny of 36-month rule transactions and indirect ownership changes; expanded prepayment and post-payment review of claims, ordering practitioners, utilization, and geographic patterns; increased attention to practitioner licensure and certification documentation; and monitoring of changes in EFT instructions and bank accounts. For home health, CMS review may focus on certification, face-to-face encounter, and plan-of-care documentation; for hospice, on terminal-status certification, length-of-stay, live-discharge, and patient-contact patterns.

What Providers, Investors, and Deal Parties Should Do Now

Prepare for enhanced oversight. Assemble current organizational charts, ownership disclosures, practitioner information, EFT instructions, and bank-account controls. Confirm that ordering and certifying practitioners are properly enrolled and licensed. Review face-to-face encounters, plans of care, certifications, and telehealth documentation. Use internal analytics to identify unusual ordering, utilization, geography, and beneficiary patterns. Have tested protocols in place for responding to audits, investigations, and subpoenas.

Strengthen compliance infrastructure. Ensure your compliance program addresses the high-risk service areas CMS and Congress have identified: home health, hospice, DMEPOS, behavioral health, personal care, ABA therapy, and non-emergency medical transportation. Maintain robust internal reporting mechanisms, including anonymous hotlines and non-retaliation policies. Recent DOJ enforcement actions – including a $32 million False Claims Act settlement holding individual executives personally liable – underscore that boards, officers, and senior managers should understand their potential individual exposure and ensure compliance is a governance-level priority.

Monitor developments. Track any extension or refinement of the moratoria, the CY 2027 provider-enrollment proposal, the anticipated CRUSH regulation, CMS guidance on hospice telehealth, and state Medicaid or CHIP enrollment actions. The hospice moratorium has raised questions about telehealth recertification encounters; CMS has indicated the moratorium does not affect existing hospices' telehealth use, but providers should treat this as a live compliance watch item and maintain contingency capacity for in-person encounters.

The combination of three nationwide enrollment moratoria, the CRUSH initiative, the OIG white paper's enforcement roadmap, and parallel congressional and state investigations means that providers, investors, and deal parties across home health, hospice, and DMEPOS should expect sustained, intensifying scrutiny of enrollment, billing, ownership, and compliance. Those who prepare now will be best positioned to navigate what comes next.

* * *

If you have questions about how these developments may affect your organization or would like assistance assessing your compliance program, we encourage you to reach out to the authors of this alert or any member of Baker Donelson.

Email Disclaimer

NOTICE: The mailing of this email is not intended to create, and receipt of it does not constitute an attorney-client relationship. Anything that you send to anyone at our Firm will not be confidential or privileged unless we have agreed to represent you. If you send this email, you confirm that you have read and understand this notice.
Cancel Accept