The New National Fraud Enforcement Division
What Every Wound Care Provider Should Be Doing Right Now
B. Moira Sykstus, CHC, CPCO, CPMA, RRT, DAPWCA
Chief Compliance Officer, Redemption Revenue & Compliance Services
Quick Read Summary
The Department of Justice has formally established the National Fraud Enforcement Division, reinforcing a national approach centered on fraud involving taxpayer-funded programs, data-driven investigative techniques, and interagency coordination.
For wound care providers, the immediate response should be practical: build a functioning compliance program, audit records routinely, monitor billing and utilization data, and strengthen oversight of high-risk services before an outside reviewer identifies the problem.
- The enforcement environment is increasingly data-driven and coordinated.
- Debridement, Cellular and Acellular Matrix-like Products (CAMPs), modifier use, medical necessity, wound measurement consistency, and same-day E/M billing deserve focused review.
- RAC, UPIC, SMRC, MAC, and TPE activity can expose weaknesses in documentation, coding, credentialing, utilization, and internal oversight.
- Claims payment is not proof of compliance.
- If your organization does not have a compliance program, start one. If you are not auditing records, start now.
A Structural Change with Practical Consequences
The U.S. Department of Justice published a final rule on August 18, 2026, formally establishing the National Fraud Enforcement Division in 28 CFR Part 0, effective August 24, 2026. The rule describes a mission focused on fraud against taxpayer dollars and taxpayer-funded programs, supported by advanced, data-driven investigative techniques and coordination with program agencies and law-enforcement partners.
The rule does not create new substantive healthcare fraud statutes. Its practical importance is organizational: fraud enforcement is being centralized, authorities are being formally assigned, and data and coordination are central to the Division’s mission.
For wound care providers, the relevant question is not how the Department of Justice organizes itself. The relevant question is whether the practice can demonstrate that its claims, documentation, product utilization, and clinical decision-making are accurate, medically necessary, and consistent with applicable requirements.
If You Do Not Have a Compliance Program, Start One
A compliance program should function as an internal early-warning system, not as a binder placed on a shelf. It should help the organization identify risk, educate clinicians and staff, investigate concerns, implement corrective action, and confirm that corrective action worked.
- Written compliance standards and policies
- A designated compliance leader with authority and access to leadership
- Routine education for clinicians, coders, billers, and operational staff
- Confidential pathways for reporting concerns
- Risk-based auditing and monitoring
- Consistent corrective action and follow-up
- Documented oversight by practice leadership or the governing body
Starting Point
A smaller practice does not need a complicated bureaucracy. It does need clear accountability, written expectations, a reporting pathway, scheduled audits, documented corrective action, and leadership that acts on findings.
The Hidden Risk: A Compliance Program That Exists Only on Paper
A compliance program that exists only on paper may create a false sense of security and can increase exposure when written expectations, audit findings, reported concerns, or corrective-action commitments are not carried out.
Once an organization adopts policies and oversight processes, leadership should be prepared to demonstrate that the program is active: risks are identified, concerns are investigated, corrective action is implemented, and follow-up confirms that the correction worked.
A policy that is routinely ignored, an audit finding that is not addressed, or a known weakness that repeatedly recurs may raise questions about the effectiveness of organizational oversight and the credibility of the compliance program.
Typical Compliance Program Failures
- Policies and procedures are outdated, generic, or inconsistent with current operations.
- Internal audits identify deficiencies, but findings are not assigned, corrected, or tracked to closure.
- The same documentation, coding, billing, or utilization issues recur in later reviews.
- Education is provided without follow-up monitoring to determine whether performance improved.
- Compliance committee or leadership oversight exists on paper, but meetings, decisions, and follow-up are not documented.
- Employee complaints, hotline reports, or other concerns are not investigated and resolved promptly.
- Corrective-action plans are created, but implementation and effectiveness are never verified.
- High-risk services are recognized, but no risk-based audit or monitoring plan is maintained.
- Overpayments or potential billing errors are identified, but escalation, evaluation, and resolution are delayed.
- Compliance responsibility is assigned without sufficient authority, access to leadership, resources, or accountability.
Compliance Risk Spotlight
A compliance plan on a shelf creates a false sense of security. The strongest compliance programs are actively used, routinely tested, supported by leadership, and able to demonstrate timely corrective action when risks are identified.
If You Are Not Auditing Records, Start Now
Claims can be paid and later reviewed. A clean remittance does not establish that documentation supported the service; the correct code was selected, or all coverage and billing requirements were satisfied.
Begin with a baseline audit across high-risk services and providers. Review a meaningful sample from recently completed episodes, trace each claim back to the signed medical record, and document the finding, education, correction, and re-audit.
Wound Care-Specific Audit Priorities
Medical Necessity and the Wound-Healing Narrative
The record should explain the wound’s status, clinical barriers to healing, treatment goals, response to prior interventions, and the rationale for the current plan. An independent reviewer should be able to understand why the service was reasonable on that date.
Debridement Services
Audit the documented tissue removed, depth, surface area, method, wound findings, clinical rationale, and consistency between the procedure note and the code submitted. Repetitive language should not substitute for patient-specific findings.
Wound Measurements and Progress
Review length, width, depth, area when used, wound-bed findings, drainage, tissue characteristics, and serial change. Inconsistent measurement methods, unexplained shifts, and copied-forward values weaken the record.
Cellular and Acellular Matrix-like Products (CAMPs)
Confirm patient selection, relevant prior treatment, wound-bed preparation, product choice, size and units, application details, wastage reporting when applicable, response to treatment, and the rationale for each subsequent application.
The record should explain why a CAMP was selected at that stage of care and how continued use fit the overall plan.
Evaluation and Management Services with Procedures
When an E/M service is separately reported on the same date, verify that the documentation supports a distinct, medically necessary service beyond the usual pre- and post-procedure work.
Modifier Utilization
Monitor provider-level use of modifiers 25, 24, 59 and related modifiers, repeat-procedure modifiers, and wastage modifiers. Focused review should determine whether the documentation supports the modifier and whether use differs materially among providers.
DMEPOS and Supply-Related Services
Where applicable, review orders, medical necessity, supplier obligations, proof of delivery, utilization, beneficiary records, enrollment, and the relationship between the furnishing entity and the treating practice.
Place of Service, Credentialing, and Billing Entity
Verify that the rendering provider, billing entity, enrollment status, reassignment, supervision, and place of service are accurate for the date of service.
Infection, Perfusion, and Contributing Conditions
Ensure the treatment plan reflects documented infection assessment, perfusion or vascular evaluation when clinically relevant, pressure relief or off-loading, edema management, glycemic issues, nutrition, and other healing barriers.
RAC and Program-Integrity Audit Targets to Put on Your Work Plan
Audit topics change by contractor, jurisdiction, setting, and date of service. The following are practical wound care exposure areas for an internal risk assessment, not a statement that every contractor currently lists each item as an active target.
High-Cost or Repeated CAMP Claims
Can the record support eligibility, product selection, units, application frequency, wastage, and continued medical necessity for every date?
Debridement Code Depth and Area
Does the note support the tissue depth and total surface area represented by the submitted code and add-on units?
Repeated Services with Limited Documented Progress
Does the plan change when expected progress is not achieved, and is the clinical reasoning documented?
Same-Day E/M and Procedure Billing
Is a significant, separately identifiable E/M service apparent from the record?
Modifier Outliers
Can each modifier be supported, and can variation among clinicians be explained?
Incorrect Entity, Enrollment, or Place of Service
Were claims submitted under the correct provider and entity, with accurate enrollment and setting information?
Missing Orders, Signatures, or Certifications
Are records complete, authenticated, timely, and linked to the billed service?
Insufficient Conservative-Treatment History
When an applicable requirement or clinical rationale depends on prior management, does the record state what was provided, for how long, and how the wound responded?
Product Units and Wastage
Do product size, wound size, amount applied, amount discarded, HCPCS units, and modifiers reconcile?
Utilization Above Peers or Rapid Growth
Can leadership explain growth, patient mix, referral patterns, staffing, outcomes, and controls that expanded with the service line?
Know Your Data Before Someone Else Reviews It
The Fraud Division’s formal mission includes advanced, data-driven investigative techniques. Wound care organizations should apply the same discipline internally. A data flag is not proof of misconduct, but it is a reason to validate the underlying claims and records.
- Peer comparison by specialty, setting, location, diagnosis mix, service mix, and patient population
- Provider-level analysis of codes, modifiers, units, frequency, allowed amounts, and beneficiaries
- Longitudinal trend analysis for rapid growth, abrupt coding changes, and new high-volume services
- Claims-to-record reconciliation for selected dates of service
- Code-pair and episode analysis for repeated procedures, same-day services, and unusual combinations
- CAMP product, size, unit, wastage, application-frequency, and provider-variation reports
- Geographic and temporal review for implausible travel, overlapping services, or excessive daily volume
- Denial, appeal, refund, complaint, and audit-finding trend analysis
A Practical 90-Day Audit-Readiness Plan
Days 1–30: Establish Control
Assign compliance responsibility; adopt or refresh the compliance plan; identify high-risk services; preserve applicable policies and coverage materials by date of service; and inventory prior audits, refunds, denials, and complaints.
Days 31–60: Test the Records and the Data
Audit selected records across clinicians and service lines. Reconcile documentation to claims. Review debridement, CAMPs, modifiers, E/M with procedures, wound measurements, product units and wastage, credentialing, and place of service. Compare utilization among providers.
Days 61–90: Correct and Verify
Educate staff using the actual findings, correct workflows, evaluate potential overpayments with appropriate professional guidance, document corrective action, and perform a focused re-audit to confirm sustained improvement.
Before the Audit Letter Arrives
- Create a centralized process for mail, portal notices, ADRs, subpoenas, and contractor requests.
- Designate who will lead clinical review, coding review, legal review, communication, and production.
- Confirm that the submitted record is complete, legible, authenticated, date-specific, and organized.
- Do not alter a medical record after receiving a request. Follow compliant late-entry, addendum, and correction policies.
- Build a claim-to-document crosswalk so reviewers can locate the support for each billed service and unit.
- Perform an independent pre-submission review and preserve exactly what was submitted.
- Track deadlines, determinations, repayment activity, and appeal rights in a single audit log.
Conclusion: Proactive Audit Readiness
The establishment of the National Fraud Enforcement Division does not change the fundamentals of wound care compliance. It reinforces the direction of travel: centralized enforcement, coordinated investigations, and increasing reliance on data to identify unusual billing and utilization patterns.
The appropriate response is preparation, not panic. If your organization does not have a compliance program, start one. If you are not auditing records, start now. If you cannot explain your debridement patterns, CAMP utilization, modifiers, product units, documentation trends, and provider-level variation, begin reviewing the data before an auditor does.
Proactive audit readiness means finding concerns early, correcting them responsibly, educating clinicians and staff, and proving that corrective action worked. In the current environment, that is not merely a compliance best practice. It is an essential part of protecting patients, providers, and the long-term viability of wound care services.
Author
B. Moira Sykstus, CHC, CPCO, CPMA, RRT, DAPWCA is Chief Compliance Officer for Redemption Revenue & Compliance Services. Her work focuses on healthcare compliance, Medicare audit readiness and defense, revenue-cycle risk, wound care documentation, and provider education.
Sources and Editorial Note
- U.S. Department of Justice, Final Rule, “Establishing the National Fraud Enforcement Division,” 91 Fed. Reg. 53357 (Aug. 18, 2026), effective Aug. 24, 2026.
- The wound care audit priorities and readiness strategies in this article are educational recommendations and risk-assessment topics. Active audit issues, coverage requirements, and documentation standards vary by contractor, jurisdiction, setting, payer, product, and date of service. Verify requirements applicable to the claim under review.
Disclaimer
This article is provided by Redemption Revenue & Compliance Services for general educational and informational purposes only. It is not legal advice, does not create an attorney-client or consultant-client relationship, and should not be relied upon as a substitute for advice from qualified legal counsel or other professionals familiar with an organization’s specific facts.
Laws, regulations, agency guidance, coverage requirements, enforcement priorities, and interpretations may change. Providers and suppliers remain responsible for evaluating and complying with all requirements applicable to their services, claims, contracts, and operations.
Examples of analytics, audit exposure, and compliance risks are illustrative and are not findings of wrongdoing, exhaustive lists, or descriptions of every method used by government agencies. Receipt or use of this article does not guarantee compliance, payment, audit outcomes, or protection from investigation or enforcement action.