8.1 Exclusion Screening (OIG LEIE, SAM.gov) & Credentialing Due Diligence
Key Takeaways
- The HHS Office of Inspector General (OIG) maintains the List of Excluded Individuals/Entities (LEIE), updated monthly, which prohibits excluded parties from receiving payment directly or indirectly under federal healthcare programs.
- Employing or contracting with an excluded individual or entity creates severe liability under the Civil Monetary Penalties Law (CMPL), with fines up to $20,000+ per item or service billed plus treble damages (3x amount claimed).
- While the OIG LEIE focuses specifically on healthcare program exclusions, the System for Award Management (SAM.gov), maintained by the General Services Administration (GSA), tracks government-wide procurement and non-procurement debarments.
- Healthcare organizations must conduct pre-employment and monthly ongoing screening for all employees, medical staff, vendors, contractors, and temporary personnel against both LEIE and SAM.gov databases.
- Primary Source Verification (PSV) is required for professional state licensure, DEA registrations, board certifications, and National Practitioner Data Bank (NPDB) queries prior to hiring or granting clinical privileges.
8.1 Exclusion Screening (OIG LEIE, SAM.gov) & Credentialing Due Diligence
Healthcare compliance programs must establish rigorous pre-employment screening and ongoing monitoring controls to ensure that no individual or entity barred from federal healthcare programs is employed, contracted, or granted clinical privileges. Element 5 of the Office of Inspector General (OIG) Compliance Program Guidance emphasizes that screening and credentialing due diligence are primary defense mechanisms against fraud, waste, and abuse.
Statutory Authority for Exclusions: Mandatory vs. Permissive
The Department of Health and Human Services (HHS) derives its exclusion authority primarily from Sections 1128 and 1156 of the Social Security Act. Exclusions fall into two distinct statutory categories:
1. Mandatory Exclusions
By law, the OIG must exclude individuals or entities convicted of specific criminal offenses for a minimum period of 5 years. Mandatory exclusion triggers include:
- Medicare or Medicaid Fraud: Convictions related to the delivery of an item or service under Medicare, Medicaid, TRICARE, or any state health program.
- Patient Abuse or Neglect: Convictions related to patient abuse, neglect, or harm in connection with the delivery of healthcare.
- Felony Health-Related Fraud: Felony convictions relating to healthcare fraud, theft, embezzlement, breach of fiduciary responsibility, or financial misconduct.
- Felony Controlled Substance Convictions: Felony convictions relating to the unlawful manufacture, distribution, prescription, or dispensing of controlled substances.
2. Permissive Exclusions
The OIG has discretionary authority to exclude individuals or entities based on other misconduct. Permissive exclusion periods vary depending on the statutory ground and aggravating or mitigating circumstances. Permissive triggers include:
- Misdemeanor convictions related to healthcare fraud or controlled substances.
- Revocation, suspension, or surrender of a healthcare license for reasons bearing on professional competence, professional performance, or financial integrity.
- Submission of claims for excessive charges, unnecessary services, or services failing to meet professionally recognized standards of care.
- Default on health education loan or scholarship obligations.
- Entity ownership or control by an excluded individual (where an excluded person holds 5% or more interest or serves as an officer/director).
Comparing OIG LEIE vs. SAM.gov
Healthcare compliance officers must understand the operational and legal distinctions between the two primary federal exclusion databases.
| Feature | OIG LEIE (List of Excluded Individuals/Entities) | SAM.gov (System for Award Management) |
|---|---|---|
| Managing Agency | Department of Health and Human Services Office of Inspector General (HHS-OIG) | General Services Administration (GSA) |
| Primary Scope | Healthcare-specific statutory exclusions under Sections 1128 & 1156 of Social Security Act | Government-wide procurement and non-procurement debarments and suspensions |
| Update Frequency | Monthly downloadable database updates | Real-time / Daily continuous updates |
| Key Data Fields | Full Name, NPI, DOB, Address, Specialty, Exclusion Type, Reinstatement Date | Name, Unique Entity ID (UEI), CAGE Code, Exclusion Type, Active/Inactive Status |
| Direct Legal Effect | Prohibition on billing or receiving payment under Medicare, Medicaid, TRICARE | Prohibition on receiving federal contracts, subcontracts, grants, or federal financial assistance |
| Compliance Scope | Mandatory for all healthcare providers receiving federal program reimbursement | Mandatory for federal contractors, grant recipients, and vendor risk management |
The Legal Effect of Exclusion & Civil Monetary Penalties Law (CMPL) Risk
The "Effect of Exclusion" Prohibition
When an individual or entity is excluded by the OIG, no federal healthcare program payment may be made for any items or services furnished, ordered, or prescribed by an excluded person.
Critical Compliance Rule: The prohibition extends far beyond direct patient care. It applies to all administrative, managerial, operational, and support roles if the individual's salary or services are funded directly or indirectly, in whole or in part, by federal healthcare program funds. Roles subject to exclusion prohibition include billing clerks, IT specialists, medical coders, executives, scrub techs, maintenance staff, and contracted consultants.
Civil Monetary Penalties Law (CMPL) Liability
Under Section 1128A(a)(6) of the Social Security Act, employing or contracting with an excluded individual exposes the healthcare organization to severe financial and administrative penalties:
- Civil Monetary Penalties: Up to $10,000 to $20,000+ per item or service billed during the period of exclusion (adjusted annually for inflation under the Federal Civil Penalties Inflation Adjustment Act).
- Treble Damages: Assessment of up to 3 times the total amount claimed for each item or service furnished by the excluded individual.
- Repayment Obligation: Complete refund of all federal healthcare program funds collected for items or services furnished, ordered, or prescribed by the excluded party.
- Corporate Integrity Agreements (CIAs): Increased regulatory oversight, mandatory independent audit monitoring, and potential loss of billing privileges.
The "Knew or Should Have Known" Standard
The CMPL enforces a scienter standard of constructive knowledge. The government does not need to prove that the entity intended to hire an excluded individual. Failing to conduct regular, monthly screening establishes that the organization "should have known" of the exclusion, satisfying the legal standard for liability.
Monthly Exclusion Screening Workflow & Match Resolution
To satisfy regulatory expectations issued in the OIG’s 2013 Special Advisory Bulletin on the Effect of Exclusion, healthcare providers must implement a structured, monthly screening workflow.
[Pre-Employment & Monthly Active Workforce Roster]
│
▼
[Automated Query against OIG LEIE & SAM.gov Databases]
│
┌────────────┴────────────┐
▼ ▼
[No Match Found] [Potential Match ('Hit')]
│ │
[Document Log & [Initiate Match Verification Workflow]
Store Proof] │
▼
[Compare SSN / EIN / NPI / Alias]
│
┌─────────────┴─────────────┐
▼ ▼
[False Positive Hit] [Confirmed Match]
│ │
[Document Clearance 1. Reassign/Suspend immediately
& Close File] 2. Confirm with Legal & HR
3. Terminate access/contract
4. Calculate billing impact
5. OIG Self-Disclosure (SDP)
Essential Operational Controls for Monthly Screening
- Comprehensive Screening Universe: The screening pool must encompass all full-time, part-time, PRN, temporary, contracted, and volunteer staff, as well as members of the Board of Directors, ordering/referring physicians, and third-party vendor representatives.
- Alias and Maiden Name Capture: Screening databases using only current legal names is insufficient. Compliance software must query maiden names, middle names, hyphenated names, legal aliases, and prior operating names.
- SSN/EIN Verification for Confirmed Matches: A name-only match is considered a potential "hit." Compliance officers must verify the match by checking the candidate’s Social Security Number (SSN) or Employer Identification Number (EIN) directly against the OIG’s online verification tool or SAM.gov record.
- Immediate Protocol Upon Confirmed Match:
- Step 1: Immediately remove the individual from providing services or billing federal programs (reassign to zero-federal-funding roles or place on administrative suspension).
- Step 2: Escalate to Legal Counsel and Human Resources to initiate contract termination or employment separation.
- Step 3: Perform a retrospective look-back audit to identify all claims, orders, or prescriptions originating from or processed by the excluded individual during their tenure.
- Step 4: Utilize the OIG Self-Disclosure Protocol (SDP) to self-report the violation, repay overpayments, and negotiate reduced CMPL multipliers (typically 1.5x damages under SDP versus 3x damages in enforcement actions).
Healthcare Credentialing & Primary Source Verification (PSV)
In addition to exclusion database screening, healthcare entities must maintain rigorous credentialing procedures to verify professional competence, licensure, and background integrity prior to employment or medical staff appointment.
Primary Source Verification (PSV) Defined
Primary Source Verification involves obtaining direct confirmation of an applicant’s credentials from the original issuing authority, rather than accepting secondary documents (such as copies of diplomas or state licenses provided by the applicant).
Mandatory Components of Credentialing Due Diligence
- State Professional Licensure: Direct verification with state licensing boards (e.g., State Medical Board, Board of Nursing) to confirm active status, expiration date, scope of practice, and presence of disciplinary restrictions or probations.
- DEA Controlled Substance Registration: Verification with the Drug Enforcement Administration for prescribers.
- Board Certification & Educational Verification: Direct contact with medical schools, residency programs, and specialty boards.
- National Practitioner Data Bank (NPDB) Queries: Mandatory queries under the Health Care Quality Improvement Act (HCQIA) during initial medical staff credentialing and at least every 2 years during re-credentialing. The NPDB contains confidential reports on:
- Medical malpractice payments made on behalf of practitioners.
- Adverse licensure and state board actions.
- Clinical privilege suspensions or revocations lasting over 30 days.
- Professional society membership sanctions.
- Criminal Background Checks: Pre-employment finger-print or nationwide criminal database checks for state and federal offenses.
Real-World Compliance Case Scenario
Scenario: Metro Health System hires a Senior Patient Financial Services Manager responsible for supervising Medicare billing. During onboarding, HR checked state licensing but neglected to run an OIG LEIE query. Two years later, during a routine internal compliance audit, the compliance team discovers that the manager had been permissively excluded by the OIG 4 years prior following a misdemeanor conviction for health-related financial fraud in another state.
Compliance Impact & Resolution: Over the 24-month employment period, the manager supervised the submission of 12,000 Medicare claims totaling $6 million in reimbursements. Even though the manager did not provide direct patient care, their administrative supervision of federal billing fell directly under the exclusion prohibition.
Remediation Action: The Compliance Officer immediately suspended the manager, terminated employment, engaged external legal counsel, and initiated a self-disclosure under the OIG Self-Disclosure Protocol. The health system calculated the total salary and benefits paid to the manager using federal funds, refunded the overpayment, and paid a negotiated CMPL settlement of $450,000 to resolve liability, avoiding formal exclusion of the facility itself.
Under HHS-OIG exclusion authorities, which of the following offenses triggers a MANDATORY exclusion for a minimum period of 5 years?
What is the legal standard of knowledge enforced under the Civil Monetary Penalties Law (CMPL) when a healthcare provider employs an excluded individual?
An excluded individual is barred from receiving payment under federal healthcare programs. To which of the following hospital positions does this prohibition apply?
When credentialing a physician for hospital medical staff privileges, what is the mandatory primary source verification tool used to check adverse licensure actions, medical malpractice payments, and clinical privilege suspensions?