8.1 Exclusion Screening (OIG LEIE, SAM.gov) & Credentialing Due Diligence

Key Takeaways

  • The HHS Office of Inspector General (OIG) maintains the List of Excluded Individuals/Entities (LEIE), updated monthly, which prohibits excluded parties from receiving payment directly or indirectly under federal healthcare programs.
  • Employing or contracting with an excluded individual or entity creates severe liability under the Civil Monetary Penalties Law (CMPL), with fines up to $20,000+ per item or service billed plus treble damages (3x amount claimed).
  • While the OIG LEIE focuses specifically on healthcare program exclusions, the System for Award Management (SAM.gov), maintained by the General Services Administration (GSA), tracks government-wide procurement and non-procurement debarments.
  • Healthcare organizations must conduct pre-employment and monthly ongoing screening for all employees, medical staff, vendors, contractors, and temporary personnel against both LEIE and SAM.gov databases.
  • Primary Source Verification (PSV) is required for professional state licensure, DEA registrations, board certifications, and National Practitioner Data Bank (NPDB) queries prior to hiring or granting clinical privileges.
Last updated: July 2026

8.1 Exclusion Screening (OIG LEIE, SAM.gov) & Credentialing Due Diligence

Healthcare compliance programs must establish rigorous pre-employment screening and ongoing monitoring controls to ensure that no individual or entity barred from federal healthcare programs is employed, contracted, or granted clinical privileges. Element 5 of the Office of Inspector General (OIG) Compliance Program Guidance emphasizes that screening and credentialing due diligence are primary defense mechanisms against fraud, waste, and abuse.


Statutory Authority for Exclusions: Mandatory vs. Permissive

The Department of Health and Human Services (HHS) derives its exclusion authority primarily from Sections 1128 and 1156 of the Social Security Act. Exclusions fall into two distinct statutory categories:

1. Mandatory Exclusions

By law, the OIG must exclude individuals or entities convicted of specific criminal offenses for a minimum period of 5 years. Mandatory exclusion triggers include:

  • Medicare or Medicaid Fraud: Convictions related to the delivery of an item or service under Medicare, Medicaid, TRICARE, or any state health program.
  • Patient Abuse or Neglect: Convictions related to patient abuse, neglect, or harm in connection with the delivery of healthcare.
  • Felony Health-Related Fraud: Felony convictions relating to healthcare fraud, theft, embezzlement, breach of fiduciary responsibility, or financial misconduct.
  • Felony Controlled Substance Convictions: Felony convictions relating to the unlawful manufacture, distribution, prescription, or dispensing of controlled substances.

2. Permissive Exclusions

The OIG has discretionary authority to exclude individuals or entities based on other misconduct. Permissive exclusion periods vary depending on the statutory ground and aggravating or mitigating circumstances. Permissive triggers include:

  • Misdemeanor convictions related to healthcare fraud or controlled substances.
  • Revocation, suspension, or surrender of a healthcare license for reasons bearing on professional competence, professional performance, or financial integrity.
  • Submission of claims for excessive charges, unnecessary services, or services failing to meet professionally recognized standards of care.
  • Default on health education loan or scholarship obligations.
  • Entity ownership or control by an excluded individual (where an excluded person holds 5% or more interest or serves as an officer/director).

Comparing OIG LEIE vs. SAM.gov

Healthcare compliance officers must understand the operational and legal distinctions between the two primary federal exclusion databases.

FeatureOIG LEIE (List of Excluded Individuals/Entities)SAM.gov (System for Award Management)
Managing AgencyDepartment of Health and Human Services Office of Inspector General (HHS-OIG)General Services Administration (GSA)
Primary ScopeHealthcare-specific statutory exclusions under Sections 1128 & 1156 of Social Security ActGovernment-wide procurement and non-procurement debarments and suspensions
Update FrequencyMonthly downloadable database updatesReal-time / Daily continuous updates
Key Data FieldsFull Name, NPI, DOB, Address, Specialty, Exclusion Type, Reinstatement DateName, Unique Entity ID (UEI), CAGE Code, Exclusion Type, Active/Inactive Status
Direct Legal EffectProhibition on billing or receiving payment under Medicare, Medicaid, TRICAREProhibition on receiving federal contracts, subcontracts, grants, or federal financial assistance
Compliance ScopeMandatory for all healthcare providers receiving federal program reimbursementMandatory for federal contractors, grant recipients, and vendor risk management

The Legal Effect of Exclusion & Civil Monetary Penalties Law (CMPL) Risk

The "Effect of Exclusion" Prohibition

When an individual or entity is excluded by the OIG, no federal healthcare program payment may be made for any items or services furnished, ordered, or prescribed by an excluded person.

Critical Compliance Rule: The prohibition extends far beyond direct patient care. It applies to all administrative, managerial, operational, and support roles if the individual's salary or services are funded directly or indirectly, in whole or in part, by federal healthcare program funds. Roles subject to exclusion prohibition include billing clerks, IT specialists, medical coders, executives, scrub techs, maintenance staff, and contracted consultants.

Civil Monetary Penalties Law (CMPL) Liability

Under Section 1128A(a)(6) of the Social Security Act, employing or contracting with an excluded individual exposes the healthcare organization to severe financial and administrative penalties:

  • Civil Monetary Penalties: Up to $10,000 to $20,000+ per item or service billed during the period of exclusion (adjusted annually for inflation under the Federal Civil Penalties Inflation Adjustment Act).
  • Treble Damages: Assessment of up to 3 times the total amount claimed for each item or service furnished by the excluded individual.
  • Repayment Obligation: Complete refund of all federal healthcare program funds collected for items or services furnished, ordered, or prescribed by the excluded party.
  • Corporate Integrity Agreements (CIAs): Increased regulatory oversight, mandatory independent audit monitoring, and potential loss of billing privileges.

The "Knew or Should Have Known" Standard

The CMPL enforces a scienter standard of constructive knowledge. The government does not need to prove that the entity intended to hire an excluded individual. Failing to conduct regular, monthly screening establishes that the organization "should have known" of the exclusion, satisfying the legal standard for liability.


Monthly Exclusion Screening Workflow & Match Resolution

To satisfy regulatory expectations issued in the OIG’s 2013 Special Advisory Bulletin on the Effect of Exclusion, healthcare providers must implement a structured, monthly screening workflow.

[Pre-Employment & Monthly Active Workforce Roster]
                        │
                        ▼
 [Automated Query against OIG LEIE & SAM.gov Databases]
                        │
           ┌────────────┴────────────┐
           ▼                         ▼
   [No Match Found]           [Potential Match ('Hit')]
           │                         │
   [Document Log &           [Initiate Match Verification Workflow]
    Store Proof]                     │
                                     ▼
                       [Compare SSN / EIN / NPI / Alias]
                                     │
                       ┌─────────────┴─────────────┐
                       ▼                           ▼
             [False Positive Hit]           [Confirmed Match]
                       │                           │
               [Document Clearance         1. Reassign/Suspend immediately
                & Close File]              2. Confirm with Legal & HR
                                           3. Terminate access/contract
                                           4. Calculate billing impact
                                           5. OIG Self-Disclosure (SDP)

Essential Operational Controls for Monthly Screening

  1. Comprehensive Screening Universe: The screening pool must encompass all full-time, part-time, PRN, temporary, contracted, and volunteer staff, as well as members of the Board of Directors, ordering/referring physicians, and third-party vendor representatives.
  2. Alias and Maiden Name Capture: Screening databases using only current legal names is insufficient. Compliance software must query maiden names, middle names, hyphenated names, legal aliases, and prior operating names.
  3. SSN/EIN Verification for Confirmed Matches: A name-only match is considered a potential "hit." Compliance officers must verify the match by checking the candidate’s Social Security Number (SSN) or Employer Identification Number (EIN) directly against the OIG’s online verification tool or SAM.gov record.
  4. Immediate Protocol Upon Confirmed Match:
    • Step 1: Immediately remove the individual from providing services or billing federal programs (reassign to zero-federal-funding roles or place on administrative suspension).
    • Step 2: Escalate to Legal Counsel and Human Resources to initiate contract termination or employment separation.
    • Step 3: Perform a retrospective look-back audit to identify all claims, orders, or prescriptions originating from or processed by the excluded individual during their tenure.
    • Step 4: Utilize the OIG Self-Disclosure Protocol (SDP) to self-report the violation, repay overpayments, and negotiate reduced CMPL multipliers (typically 1.5x damages under SDP versus 3x damages in enforcement actions).

Healthcare Credentialing & Primary Source Verification (PSV)

In addition to exclusion database screening, healthcare entities must maintain rigorous credentialing procedures to verify professional competence, licensure, and background integrity prior to employment or medical staff appointment.

Primary Source Verification (PSV) Defined

Primary Source Verification involves obtaining direct confirmation of an applicant’s credentials from the original issuing authority, rather than accepting secondary documents (such as copies of diplomas or state licenses provided by the applicant).

Mandatory Components of Credentialing Due Diligence

  • State Professional Licensure: Direct verification with state licensing boards (e.g., State Medical Board, Board of Nursing) to confirm active status, expiration date, scope of practice, and presence of disciplinary restrictions or probations.
  • DEA Controlled Substance Registration: Verification with the Drug Enforcement Administration for prescribers.
  • Board Certification & Educational Verification: Direct contact with medical schools, residency programs, and specialty boards.
  • National Practitioner Data Bank (NPDB) Queries: Mandatory queries under the Health Care Quality Improvement Act (HCQIA) during initial medical staff credentialing and at least every 2 years during re-credentialing. The NPDB contains confidential reports on:
    • Medical malpractice payments made on behalf of practitioners.
    • Adverse licensure and state board actions.
    • Clinical privilege suspensions or revocations lasting over 30 days.
    • Professional society membership sanctions.
  • Criminal Background Checks: Pre-employment finger-print or nationwide criminal database checks for state and federal offenses.

Real-World Compliance Case Scenario

Scenario: Metro Health System hires a Senior Patient Financial Services Manager responsible for supervising Medicare billing. During onboarding, HR checked state licensing but neglected to run an OIG LEIE query. Two years later, during a routine internal compliance audit, the compliance team discovers that the manager had been permissively excluded by the OIG 4 years prior following a misdemeanor conviction for health-related financial fraud in another state.

Compliance Impact & Resolution: Over the 24-month employment period, the manager supervised the submission of 12,000 Medicare claims totaling $6 million in reimbursements. Even though the manager did not provide direct patient care, their administrative supervision of federal billing fell directly under the exclusion prohibition.

Remediation Action: The Compliance Officer immediately suspended the manager, terminated employment, engaged external legal counsel, and initiated a self-disclosure under the OIG Self-Disclosure Protocol. The health system calculated the total salary and benefits paid to the manager using federal funds, refunded the overpayment, and paid a negotiated CMPL settlement of $450,000 to resolve liability, avoiding formal exclusion of the facility itself.

Test Your Knowledge

Under HHS-OIG exclusion authorities, which of the following offenses triggers a MANDATORY exclusion for a minimum period of 5 years?

A
B
C
D
Test Your Knowledge

What is the legal standard of knowledge enforced under the Civil Monetary Penalties Law (CMPL) when a healthcare provider employs an excluded individual?

A
B
C
D
Test Your Knowledge

An excluded individual is barred from receiving payment under federal healthcare programs. To which of the following hospital positions does this prohibition apply?

A
B
C
D
Test Your Knowledge

When credentialing a physician for hospital medical staff privileges, what is the mandatory primary source verification tool used to check adverse licensure actions, medical malpractice payments, and clinical privilege suspensions?

A
B
C
D