All resourcesBook a demo →
← All credentialing resourcesCompliance & standards

OIG & SAM Exclusion Monitoring: The Compliance Risk You Can't Ignore

OIG & SAM exclusion monitoring is the ongoing practice of screening every provider, employee, contractor, and vendor against the federal exclusion lists to confirm that no one your organization pays — or bills on behalf of — has been barred from federal health care programs. It is one of the few compliance obligations where a single missed check can convert an ordinary payroll expense into six-figure liability, because the government treats every claim tied to an excluded person as an overpayment plus a penalty. This is the risk you cannot ignore, and the good news is that it is almost entirely preventable with a disciplined monthly process.

What are the OIG LEIE and SAM.gov exclusion lists?

Two federal databases anchor exclusion screening. The first is the OIG's List of Excluded Individuals and Entities (LEIE), maintained by the HHS Office of Inspector General. A person or entity on the LEIE has been excluded from participation in Medicare, Medicaid, and all other federal health care programs, and, in the OIG's words, “can receive no payment from Federal health care programs for any items or services they furnish, order, or prescribe,” per the OIG Exclusions Program. The LEIE is searchable online and downloadable as a full database with monthly supplements at exclusions.oig.hhs.gov.

The second is SAM.gov, the federal System for Award Management, which consolidates government-wide debarments and exclusions across all federal programs — not just health care. Screening SAM.gov catches individuals and entities debarred by other agencies who may not appear on the LEIE. Because the two lists are populated differently, checking one is not a substitute for the other; a defensible program screens both, and many organizations also screen the applicable state Medicaid exclusion lists.

Why is employing an excluded person so costly?

The financial exposure is severe and specific. Under the OIG's Special Advisory Bulletin on the Effect of Exclusion, the OIG “may impose CMPs of up to $10,000 for each item or service furnished by the excluded person for which Federal program payment is sought, as well as an assessment of up to three times the amount claimed.” That $10,000 figure is a statutory baseline the OIG periodically adjusts upward for inflation, so current per-item penalties run considerably higher — and they accrue per item or service, not per person. A single excluded nurse contributing to hundreds of billed encounters can generate penalties that dwarf any salary.

The prohibition is also broader than most managers assume. The bulletin makes clear that “no Federal health care program payment may be made for any items or services furnished (1) by an excluded person or (2) at the medical direction or on the prescription of an excluded person,” and it extends even to “administrative and management services that are payable by the Federal health care programs,” whether or not those services are separately billable. In other words, an excluded person working in scheduling, IT, or billing can taint claims they never personally touched.

How often must you screen against the exclusion lists?

The OIG's guidance is explicit on timing: “OIG updates the LEIE monthly, so screening employees and contractors each month best minimizes potential overpayment and CMP liability.” Monthly is the defensible cadence, and it aligns with what many state Medicaid agencies require under federal CMS guidance. Screening annually — or only at hire — leaves an eleven-month window in which an employee could be excluded and continue generating tainted claims before you notice.

Timing at the database level matters too: exclusions can take effect on any day of the month but may not appear in the LEIE until the next monthly update, so a rigorous program re-screens every individual each month rather than assuming a clean check stays clean.

State Medicaid programs raise the stakes further. Federal guidance directs state Medicaid agencies to screen their providers monthly and to require enrolled providers to do the same for their own employees and contractors, and many states publish their own exclusion lists on top of the federal ones. An organization billing Medicaid in multiple states therefore has to screen each applicable state list — a matrix that grows quickly for multi-state groups and is easy to under-scope.

Who and what must you screen?

Scope is where programs quietly fail. A complete exclusion-monitoring program screens:

  • All credentialed providers, as a standing element of every credentialing and recredentialing file.
  • All employees, clinical and non-clinical, including administrative, billing, and management staff.
  • Contractors, locum tenens, and temporary staff.
  • Vendors and suppliers whose products or services are payable by federal programs.
  • Ordering and referring practitioners, where applicable.

Exclusion screening belongs in your onboarding workflow from day one — it is a core line item on any new-provider credentialing checklist — and then repeats monthly for the life of the relationship. It also complements, but does not replace, other primary-source checks; a clean exclusion result says nothing about license status or malpractice history, which is why it sits alongside primary-source verification and NPDB queries in a complete file.

Mandatory vs. permissive exclusions — and why reinstatement is not automatic

Not all exclusions are alike. The OIG imposes mandatory exclusions for the most serious conduct — convictions for program-related fraud, patient abuse or neglect, felony health care fraud, and felony controlled-substance offenses — each carrying a statutory minimum exclusion period. It also imposes permissive exclusions at its discretion for a wider range of conduct, such as misdemeanor fraud, license loss or surrender, or default on health-education loans. For screening purposes the distinction does not change your obligation: an excluded person is excluded regardless of the category, and the payment prohibition and CMP exposure are identical.

Reinstatement is another trap. Removal from the LEIE is not automatic when an exclusion period ends — the excluded party must apply to the OIG and receive written notice of reinstatement. A provider whose exclusion ‘expired’ on paper may therefore still be barred, and paying them still triggers liability, until the OIG formally reinstates them. Screening the live LEIE each month, rather than trusting a remembered end date, is the only way to catch this.

How do you document exclusion screening for an audit?

A screen you cannot prove is a screen you did not do. For each monthly check, retain a dated, name-matched record showing the individual or entity searched, the list or lists checked (LEIE and SAM.gov), the date, the result, and the identity of the person who performed and reviewed it. When a common name produces a potential match, document the verification steps — date of birth, SSN, license number — that ruled it in or out. This evidence is exactly what an OIG audit, a payer's delegated review, or a False Claims Act inquiry will demand, and it is a required component of an audit-ready credentialing file.

Retention closes the loop. Keep exclusion-screening records for the full audit look-back period — commonly several years — so you can demonstrate an unbroken monthly history for any individual across the entire time they were affiliated with your organization. In a False Claims Act or overpayment inquiry, the government does not ask whether you screen today; it asks you to prove you screened every month going back, and a gap in the record is treated as a gap in the program.

If a match is confirmed, the excluded person must be removed from any role connected to federally funded items or services immediately, and the organization should evaluate its self-disclosure obligations. The cost of catching an exclusion in month one is a personnel decision; the cost of catching it in an audit two years later is repayment, penalties, and treble damages. Monthly OIG and SAM screening — documented, name-matched, and never skipped — is the cheapest insurance in the entire compliance program.

See your own numbers in 60 seconds

CredTek gets providers in-network 40–60% faster — built and run by operators with decades of enterprise credentialing experience, with a human approval gate on every submission.

Run the ROI calculator →