Atlantic Health Strategies

The D.C. Nassor Case: What Behavioral Health Operators Should Learn About Employee Medicaid Fraud

Table of Contents

Ready to See Results?

From strategy through execution, Atlantic Health Strategies integrates compliance, operations, and growth into durable, measurable results. Let’s put our expertise to work for your organization.

How operators actually prevent employee Medicaid billing fraud

Operators prevent employee-level Medicaid billing fraud by running a layered fraud, waste, and abuse (FWA) program: pre-payment claim edits, session-to-claim documentation reconciliation, dual verification on high-risk CPT codes, and a written corrective action plan (CAP) framework mapped to 42 CFR § 438.608 and the OIG’s Seven Elements of an Effective Compliance Program. That is the answer. The rest of this post is how the D.C. Nassor case proves the point, and what a behavioral health operator should be doing on Monday morning.

On August 28, 2026, the U.S. Attorney’s Office for the District of Columbia announced that Said Nassor pleaded guilty to conspiracy to commit healthcare fraud, admitting his role in a scheme that caused more than $250,000 in losses to D.C. Medicaid while he worked as a Community Support Worker for a D.C. Medicaid provider serving children and adolescents. According to prosecutors, company employees were instructed to bill for the maximum number of service units allowed whether or not the services were medically necessary or provided, and to bill a full hour of telehealth even when calls were shorter. The detail that should stop every COO cold: employees were told to shave a few minutes off some claims, billing for 54 minutes instead of 60, to make the sessions appear more realistic. That is not a rogue actor. That is a documented workflow.

The numbers behind the risk (and why payers are watching)

The D.C. Nassor Case: What Behavioral Health Operators Should Learn About Employee Medicaid Fraud — The numbers behind the risk (and why payers are watching)

The scale of Medicaid payment risk is not theoretical. In its FY 2024 Improper Payments Fact Sheet, CMS reported that the Medicaid improper payment rate was 5.09%, or $31.10 billion, and 79.11% of those improper payments resulted from insufficient documentation. Insufficient documentation is exactly the vulnerability the Nassor scheme exploited. Payers know it. Auditors know it. That is why GAO has flagged Medicaid managed care as an area where HHS-OIG and state auditors have identified integrity risks including payments from managed care plans to providers for services that were not delivered or lacked necessary documentation.

Enforcement volume is climbing at the same time. According to the HHS OIG Medicaid Fraud Control Units FY 2024 Annual Report, MFCUs obtained 1,151 convictions, $961 million in criminal recoveries, $407 million in civil recoveries, and 1,042 exclusions of individuals and entities from federally funded programs. Criminal recoveries did not creep. Annual criminal recoveries jumped from $272 million in FY 2023 to $961 million in FY 2024. Two hundred and seventy-two million to nine hundred and sixty-one million in one year. Whatever your policy on FWA looked like two years ago, it is out of date.

As enforcement counsel Saul Ewing summarized in an April 2026 analysis of the FY 2025 report, “900 individuals or entities were excluded from federal health care programs in FY 2025, with 674 civil settlements and judgments.” The federal-state enforcement partnership is not slowing down.

Where operator-side controls failed in cases like Nassor

The Nassor plea reads like a checklist of missing controls. I have reviewed enough D.C. And mid-Atlantic Community Support Worker programs to know these gaps repeat. The recent Jariatu Jalloh plea in D.C. shows the same pattern: several Medicaid recipients assigned to Jalloh reported they never received services or that contact lasted only a few minutes, yet she submitted documentation claiming she rendered an hour or more of services, causing over $234,500 in fraudulent CSW claims. And in the Amstrong Chapajong case, the defendant admitted to submitting false timesheets claiming in-person PCA care and telephonic CSW services to multiple beneficiaries simultaneously while at different locations, causing $113,243 in duplicative payments.

What should have caught each of these before a claim went out the door:

  • Session-to-claim reconciliation. The EMR-generated encounter note must match the claim length, CPT, and rendering provider before submission. If a CSW documents 60 minutes but the telehealth platform log shows 22 minutes, that claim should hard-stop at pre-bill review, not clear.
  • Geolocation and device-log integrity. If a note says the service was delivered in the beneficiary’s home, the visit verification data should support it. Overlap detection catches employees who claim to be in two places at once.
  • Beneficiary-side attestation sampling. D.C. Investigators built cases in part by calling beneficiaries. If OIG investigators can do it after the fact, your compliance team can do it monthly as a sample-based audit.
  • Payer-specific level of care rules. ACT, CSW, MHRS, PHP, and IOP all have distinct hour minimums and service definitions. Billing teams who do not know the payer’s definition submit clean-looking claims that are legally false.
  • Whistleblower channel that actually works. Under the Deficit Reduction Act of 2005 and the False Claims Act, employees can and do file qui tam suits. If your internal channel is dead, the next filing is on a courthouse docket.

The audit cadence and CAP framework I recommend to operators

The regulators expect a documented program, not good intentions. Under 42 CFR § 438.608, managed care entities are required to maintain program integrity safeguards, and the OIG’s Seven Elements of an Effective Compliance Program set the floor for what a defensible internal structure looks like. Here is the cadence I build with behavioral health clients:

  1. Weekly pre-payment edit review. The billing lead pulls all claims flagged by pre-payment edits (duration mismatches, overlapping encounters, missing supervisory sign-off) and clears or holds each one with written rationale.
  2. Monthly focused chart audit. Pick a high-risk code (CPT 90837, 90834, 90791, or the state’s CSW/MHRS equivalent) and pull a random sample of 25 to 50 charts per rendering provider. Reconcile note, schedule, attendance, telehealth platform log, and claim.
  3. Quarterly FWA risk assessment. Named owner. Written findings. Compared to the OIG Work Plan’s current behavioral health focus areas.
  4. Annual external operational audit. An outside compliance team reviews scheduling, UR, documentation, and billing as a connected system. Not just charts. Not just policies.
  5. Corrective action plans that are actually used. A defensible CAP names the finding, root cause, the person responsible, the deadline, the training or system change implemented, and the post-implementation verification date. If you cannot show an auditor closed CAPs from the last 12 months, you do not have a compliance program. You have a binder.

The investigation that ended Nassor’s career was jointly conducted by the FBI Washington Field Office and the D.C. Office of the Inspector General’s Medicaid Fraud Control Unit. The same partnership structure exists in every state where AHS clients operate (with the obvious exceptions where AHS does not work). Assume your MFCU is capable of pulling telehealth platform logs, EMR audit trails, and beneficiary interviews. Build your internal controls to that standard, not to the standard of what your payer’s last desk audit asked for.

The D.C. Nassor Case: What Behavioral Health Operators Should Learn About Employee Medicaid Fraud — The audit cadence and CAP framework I recommend to operators

Frequently asked questions

What are the highest-risk CPT codes for behavioral health billing fraud?
CPT 90837 (60-minute psychotherapy), 90834 (45-minute psychotherapy), and 90791 (psychiatric diagnostic evaluation) are the codes most frequently scrutinized by OIG and UPICs in outpatient behavioral health, largely because of duration-based billing. For Medicaid-specific programs, add your state’s CSW, MHRS, ACT, PHP, and IOP codes, especially any code with a per-unit or per-hour reimbursement structure. Every one of the recent D.C. Cases involved hour-based service units.

How often should a behavioral health facility conduct internal FWA audits?
Weekly pre-payment edits, monthly focused chart audits on high-risk codes, quarterly FWA risk assessments, and an annual external operational audit. If your program is only doing an annual audit, you are two to three enforcement cycles behind where CMS and OIG expect you to be.

What does a defensible corrective action plan (CAP) look like after a billing anomaly is identified?
A defensible CAP identifies the finding, root cause, responsible owner, remediation steps (system change, training, or policy revision), completion deadline, and a post-implementation verification date with evidence. Undocumented “we fixed it” conversations do not survive an OIG or MFCU review. Auditors want to see closed CAPs, not open promises.

Are behavioral health facilities liable under the False Claims Act for an individual employee’s fraud?
Yes, when the employee acted within the scope of employment or when the organization failed to implement reasonable controls to prevent and detect the conduct. The False Claims Act (31 U.S.C. §§ 3729–3733) and Deficit Reduction Act of 2005 both incentivize whistleblowers to file qui tam actions, and prosecutors regularly name corporate entities alongside individual defendants. The Nassor plea specifically references company employees who instructed workers to bill inflated units, which is exactly the pattern that pulls the entity into liability.

What documentation reconciliation controls prevent billing for sessions that never occurred?
Three controls, running together: (1) the EMR encounter note must match the claim on duration, rendering provider, and CPT; (2) the telehealth platform or visit verification log must corroborate the note’s duration and location; and (3) a rotating sample of beneficiaries or guardians is contacted to confirm the service was received. When all three run, a scheme like the one Nassor participated in does not clear the pre-bill queue.

Request a Free Consultation

Scroll to Top