A physician in South Florida billed Medicare for over $100 million in home health services that were never provided. Patients who were perfectly healthy showed up in records as receiving daily nursing visits. The scheme ran for years before federal investigators caught it. That case made headlines, but here's what most compliance officers miss: fraud and abuse in healthcare isn't always that dramatic. Sometimes it's a coder upcoding a few visits. Sometimes it's a staff member accessing PHI out of curiosity. And sometimes it's your organization — without even knowing it.

So what is fraud and abuse in healthcare, exactly? It's any deliberate or reckless act that results in unauthorized gain, improper use of resources, or harm to patients — often involving the misuse of protected health information. And under HIPAA, the consequences land squarely on covered entities and their business associates.

Fraud vs. Abuse: They're Not the Same Thing

I've seen organizations lump fraud and abuse together as if they're interchangeable. They're not. The distinction matters because your exposure — and potential penalties — shift depending on which one applies.

Healthcare Fraud: Intent Is the Key Word

Fraud is an intentional act. It involves knowingly submitting false claims, misrepresenting services, or manipulating data for financial gain. Think double billing, phantom services, or kickback schemes. Under federal law, particularly the False Claims Act (31 U.S.C. § 3729), healthcare fraud can trigger treble damages and per-claim penalties. The Department of Justice recovered over $2.2 billion in healthcare fraud judgments and settlements in fiscal year 2022 alone.

Fraud also intersects directly with HIPAA when it involves ePHI. If someone accesses electronic health records to fabricate or alter patient data for billing purposes, that's a HIPAA violation layered on top of a fraud charge. HHS Office for Civil Rights (OCR) doesn't take a back seat in those cases.

Healthcare Abuse: Reckless but Not Always Criminal

Abuse is less clear-cut. It includes practices that are inconsistent with accepted medical, business, or fiscal standards — even when there's no intent to deceive. Ordering unnecessary tests, consistently upcoding, or billing for services at a higher complexity than warranted all fall under abuse. You don't need criminal intent. You just need a pattern that costs the system money or puts patients at risk.

The Office of Inspector General (OIG) at HHS defines abuse as practices that result in unnecessary costs to federal healthcare programs or substandard care. You can review their framework on the OIG's fraud and abuse laws page.

Where HIPAA Enters the Picture

HIPAA doesn't just govern privacy and security. Title II of the statute — the Administrative Simplification provisions — was specifically designed to combat healthcare fraud. Most people forget that. HIPAA was born, in part, as an anti-fraud law.

Section 1177 of the Social Security Act, added by HIPAA, makes it a federal crime to knowingly and willfully use a unique health identifier, or obtain individually identifiable health information, under false pretenses. The penalties escalate fast: up to $50,000 and one year in prison for basic violations, up to $250,000 and ten years if the offense involves intent to sell or use PHI for commercial advantage, personal gain, or malicious harm.

Here's what that looks like in practice. When a hospital employee snoops through records to find information about a celebrity patient and sells it to the media, that's fraud under HIPAA. When a billing manager alters diagnosis codes in the EHR to maximize reimbursement, that's fraud and abuse intertwined with a HIPAA violation.

The $5.5 Million Wake-Up Call from Memorial Healthcare System

In 2017, OCR settled with Memorial Healthcare System for $5.5 million after employees accessed the ePHI of 115,143 individuals without authorization. The employees — some of them working for an affiliated physician practice — used login credentials to access patient data that they had no legitimate reason to view. OCR's investigation found that Memorial failed to regularly review audit logs and didn't implement proper access controls.

Was that fraud? Not in the billing sense. But it was abuse of access, and it violated HIPAA's Privacy and Security Rules. Memorial also agreed to a corrective action plan requiring comprehensive workforce training and access monitoring. You can read the full resolution agreement on the HHS enforcement page.

This case drives home a critical point: your organization doesn't have to be running a billing scam to face massive penalties. Abuse of access to PHI is enough.

What Does Fraud and Abuse in Healthcare Look Like Day-to-Day?

Forget the splashy federal indictments for a moment. In my experience, the fraud and abuse risks that actually threaten most organizations are mundane and operational. Here's what I've seen:

  • Upcoding: A coder routinely selects a higher-level E/M code than documentation supports. Over thousands of encounters, this generates significant overpayments.
  • Unbundling: Billing separately for procedures that should be billed together under a single CPT code to increase reimbursement.
  • Snooping: Staff accessing patient records for personal curiosity — checking on a neighbor, an ex-spouse, or a coworker. This is PHI abuse even without financial motive.
  • Falsifying credentials: A provider misrepresenting qualifications to participate in a federal healthcare program.
  • Kickbacks: Receiving payment or gifts in exchange for patient referrals. The Anti-Kickback Statute (42 U.S.C. § 1320a-7b) makes this a federal felony.

Every one of these scenarios touches PHI. Every one creates HIPAA exposure. And every one is preventable with the right training and internal controls.

Your Compliance Program Is Your First Line of Defense

OIG has published guidance for decades outlining seven elements of an effective compliance program. If your organization doesn't have one — or has one gathering dust in a binder — you're exposed. Here are the elements that matter most for preventing fraud and abuse:

Written Policies That People Actually Read

Your code of conduct should explicitly address fraud, abuse, and PHI access. It should spell out what happens when someone violates these policies. Vague language like "employees should act ethically" doesn't cut it. Specifics do.

Workforce Training That Goes Beyond a Checkbox

Annual HIPAA training is a regulatory baseline, not a ceiling. Your staff needs to understand not just what PHI is, but why unauthorized access constitutes abuse and how billing misconduct becomes fraud. A strong training program covers both privacy rules and fraud awareness in a single, coherent curriculum. If you're looking for structured programs that address these intersections, explore the HIPAA training catalog at HIPAACertify.

Auditing and Monitoring

You need to actually review your audit logs. Memorial Healthcare System learned this the hard way. If your EHR generates access logs but nobody reviews them, you've built a surveillance camera that nobody watches. Set up automated alerts for after-hours access, high-volume record views, and access to VIP patient records.

A Reporting Mechanism That Staff Trust

Hotlines, anonymous tip forms, and open-door policies only work when employees believe they won't face retaliation. The OIG's compliance guidance specifically calls out non-retaliation protections as essential. If your staff witnesses billing irregularities or PHI snooping, they need a safe channel to report it.

What Should a Covered Entity Do Right Now?

If you're a compliance officer, practice manager, or privacy officer reading this, here's the actionable checklist:

  • Review your compliance program against OIG's seven elements. Identify gaps.
  • Audit EHR access logs from the past 90 days. Look for anomalies.
  • Confirm that your workforce training addresses both HIPAA privacy and fraud/abuse awareness. Programs like those available through HIPAACertify's workforce training courses cover both areas.
  • Update your incident response plan to include fraud and abuse scenarios — not just data breaches.
  • Brief your leadership team on the financial exposure. A single OCR settlement can dwarf the cost of a comprehensive compliance program.

The Penalties Are Getting Steeper, Not Softer

OCR's enforcement actions and the DOJ's healthcare fraud strike forces show no signs of slowing down. The HHS Office of Inspector General maintains an active Work Plan that signals audit priorities each year. In recent years, they've zeroed in on telehealth billing irregularities, lab testing schemes, and substance abuse treatment fraud.

Meanwhile, breach notification requirements under HIPAA mean that if fraud or abuse leads to unauthorized disclosure of PHI, you're also on the hook for notifying affected individuals, HHS, and potentially the media. That's reputational damage on top of financial penalties.

The Bottom Line on Fraud and Abuse in Healthcare

Fraud and abuse in healthcare aren't just about bad actors running sophisticated billing schemes. They're about the everyday lapses — the unchecked audit logs, the untrained staff, the compliance programs that exist on paper but not in practice. HIPAA was designed to address these risks, and OCR has the enforcement teeth to make violations painful.

Your organization's best protection is a culture of compliance — one built on specific policies, regular training, active monitoring, and leadership that takes these risks seriously. The organizations that invest in prevention don't just avoid penalties. They protect their patients, their staff, and their reputation.