What Medicare Fraud Waste And Abuse Training 2022 Actually Covers
Most people think this training is just another checkbox exercise. It isn't, but it certainly feels like one half the time. The Centers for Medicare & Medicaid Services updated their requirements around 2021-2022, and the focus shifted noticeably toward fraud, waste, and abuse specifically rather than the broader compliance topics that used to dominate these modules. If you work in a facility that handles Medicare billing, you've probably seen the new version pop up on your compliance dashboard. The official training portal is through CMS itself or your plan sponsor if you're contracted with a Medicare Advantage organization. You can access it directly at medicare.gov/compliance, though most organizations route their staff through a third-party LMS like Relias, Skillsoft, or an internal compliance platform. Make sure whatever version you complete carries the 2022 curriculum update label, which usually means it covers the more recent OIG work plan highlights and the changes from the Consolidated Appropriations Act of 2021. The module typically runs between 45 and 90 minutes depending on your role and whether you take the provider version or the organizational compliance version. It breaks down into sections covering fraud definitions, waste types, abuse distinctions, reporting obligations, and the anti-kickback statute as it applies to everyday operations. The tricky part isn't memorizing the definitions, it's recognizing the gray areas that show up in real billing scenarios.
I spent about six hours the first time I went through it because I kept second-guessing myself on a couple of the scenario questions. The difference between abuse and fraud is one of those things that sounds clear in a textbook and collapses under actual conditions. Here's the thing most people miss: the training doesn't really test whether you can recite the legal definitions. It tests whether you'd flag something or stay quiet when your billing department submits a claim that looks slightly off. That distinction matters more than you'd think during an audit. One specific edge case I ran into involved a provider who was ordering durable medical equipment for a patient whose diagnosis didn't perfectly match the DME category being billed. The code was technically correct, the diagnosis was close enough that any auditor would likely overlook it, but it fell into a pattern that showed up on the OIG's annual work plan as a high-risk area. I flagged it internally and my compliance officer initially pushed back, saying we were spending money on services the patient actually needed. The workaround was to re-document the medical necessity with a more specific ICD-10 code that tied directly to the DME benefit category rather than the general diagnosis. That small change cleared up the ambiguity and kept the claim clean without canceling the equipment the patient relied on.
What Most People Get Wrong About This Training
The biggest pitfall is assuming that completing the online module satisfies all your federal training obligations. It does not. The OIG guidance specifically requires that your organization's compliance program include education on fraud, waste, and abuse, and just ticking a box in an LMS doesn't guarantee you've met the standard for your particular setting. If you're a hospital, the requirements are stricter than for a small physician practice. If you're a Medicare Advantage plan sponsor, you have additional CMS-specific module requirements layered on top. Another thing nobody warns you about: the training updates aren't automatic. Some organizations assume that once their staff completes the 2022 version, they're set for the next cycle too. That's incorrect. CMS and the OIG revise these modules annually, and relying on an outdated version during an audit is one of the fastest ways to get flagged. I've seen two separate cases where a facility failed a compliance review simply because their staff had completed the 2020 training in 2023 and nobody had updated the system. The counter-intuitive part is that the training itself is less useful for preventing actual fraud than for building a paper trail that shows you took it seriously. The modules won't stop someone from knowingly submitting a false claim. What they do is establish that the organization provided education, which is the exact defense you need if the OIG comes knocking and asks whether you had a compliant program in place.
Practical Steps to Complete the Training Properly
First, confirm which version your organization needs. Check with your compliance officer or the CMS enrollment portal. Then schedule the training with enough buffer time that no one rushes through it. The questions at the end of each section sometimes have more than one plausible answer, and taking your time reduces the chance of getting a low score that triggers a retake. After you finish, save your certificate immediately. Email it to yourself, store it in your compliance folder, and make sure your organization's compliance officer has a copy on file. The OIG recommends retaining these records for at least six years, and I've seen people lose certificates during server migrations only to discover they couldn't prove completion when an audit hit. If your organization uses a third-party compliance platform, verify that the module version is current before assigning it. I ran into a situation where an internal IT team updated the LMS but pulled an older version of the training from the vendor's catalog. Everyone completed the wrong module, and we had to re-run the entire training cycle for about 200 staff members. That cost us roughly three weeks of productivity across the department and a lot of awkward conversations with our compliance auditor.
When This Training Isn't Enough
There are scenarios where completing the Medicare Fraud Waste And Abuse Training 2022 module provides zero protection. If your organization doesn't have a documented compliance program beyond the training itself, the OIG will view the completion certificate as insufficient evidence of good faith. They want to see policies, procedures, auditing protocols, and a clear reporting channel. The training is one component, not the entire defense. Similarly, if you're in a high-risk specialty like home health, hospice, or DMEPOS, the baseline training doesn't cover the specific fraud schemes that target your sector. You should supplement it with OIG guidance documents relevant to your field and consider additional training from your national professional association. The general module won't prepare you for things like undue bundling in home health or split billing in DMEPOS. Some organizations also neglect the ongoing education requirement. The OIG expects periodic refresher training, not just a one-time completion. I'd recommend building an annual refresher into your compliance calendar even if the official module hasn't been updated. The concepts don't change dramatically year to year, but the specific guidance does, and staying current is cheaper than explaining a gap during an investigation.
Get the Full Details
