Why Healthcare Fraud Is Becoming an Enterprise-Wide Risk

Healthcare fraud is becoming faster, more sophisticated and more difficult to separate from other business risks. Hospitals and health insurers must still contend with familiar schemes involving medically unnecessary services, kickbacks and false claims. However, those threats are now being amplified by artificial intelligence, stolen identities, cyberattacks and organized criminal networks.

The scale of the problem is substantial. The 2025 National Health Care Fraud Takedown resulted in charges against 324 defendants accused of participating in schemes involving more than $14.6 billion in intended losses. The cases included allegations involving genetic testing, telemedicine, durable medical equipment and prescription drugs.

Fraud Is Becoming More Organized

Healthcare fraud is no longer limited to an individual provider submitting questionable claims. Large schemes may involve marketers, technology companies, medical professionals, laboratories and shell businesses operating across multiple jurisdictions.

One case included in the 2025 enforcement action involved an alleged multinational organization accused of purchasing medical supply companies and submitting billions of dollars in fraudulent Medicare claims. For hospitals and insurers, this demonstrates the need to assess relationships across the entire payment ecosystem — not just individual claims.

Suspicious changes in ownership, sudden billing spikes, unusual referral patterns and providers operating outside their normal geographic or clinical areas may all warrant closer review.

Stolen Identities Can Redirect Healthcare Payments

Identity-based fraud also threatens the financial infrastructure supporting healthcare organizations. Criminals may use compromised patient, provider or employee information to submit claims, access payment platforms or alter banking details.

Another recent report from the Department of Health and Human Services Office of the Inspector General found that Medicare and Medicaid payments are at risk of diversion through electronic funds transfer fraud. Nearly three-fifths of surveyed payers expressed interest in adopting additional safeguards against these schemes, although some reported implementation barriers.

The FBI has also warned about criminals impersonating health insurers and fraud investigators. These criminals use convincing emails and text messages to pressure patients and providers into sharing health, financial or payment information.

Artificial Intelligence Can Scale False Claims

Artificial intelligence can improve coding, documentation and fraud detection. It can also help criminals create convincing medical records, automate false claims and test billing patterns until fraudulent submissions evade existing controls.

The Government Accountability Office recently warned that fraudsters may use AI to rapidly scale Medicare fraud schemes, including by generating large volumes of claims and fake beneficiary records. The same report found that the Centers for Medicare & Medicaid Services used analytics and administrative actions to prevent an estimated $11.9 billion in potentially fraudulent Medicare payments from fiscal years 2022 through 2024.

Healthcare Fraud Requires an Enterprise Response

Hospitals and insurers can no longer treat fraud as solely a claims or compliance issue. Identity management, cybersecurity, finance, legal, human resources and clinical operations all have roles to play.

Organizations should strengthen verification for payment and account changes, monitor provider and member credentials, analyze unusual billing behavior and establish clear escalation procedures. Employee training should also address impersonation attempts, social engineering and requests for sensitive information.

The emerging healthcare fraud landscape rewards speed and coordination. Organizations that connect their fraud, cyber and identity-protection programs will be better positioned to stop suspicious activity before it becomes a costly investigation, regulatory problem or reputational crisis.

 

LibertyID Business Solutions offers customer information security protocols, information security training, third-party vendor management, and post-breach response services—helping businesses protect consumer data and meet the FTC Safeguards Rule and state compliance requirements. The package also includes our gold-standard identity fraud restoration services for employees and their families.