It’s estimated that the Centers for Medicare & Medicaid Services (CMS) loses tens of billions of dollars each year to fraud, waste, and abuse across its benefits programs. That concern took center stage earlier this year at Guidehouse’s Healthcare Innovation Summit during a fireside chat moderated by Greg Hafer, Guidehouse Partner and CMS account lead.
Jeneen Iwugo, Acting Director of the agency’s Center for Program Integrity, spoke with Hafer about its efforts to, in her words, “crush fraud” and thwart the bad actors behind those losses.
“We've been given a very, very long leash by this administration to fight fraud, longer than we've ever been given,” said Iwugo, who leads a high-performing team of investigators and analysts charged with preventing fraud. “In the past, we picked up large fraud schemes but didn’t comb through claims with the level of precision that's been asked of us now."
The current administration has made fraud prevention a top priority across federal agencies, with CMS at the center of those efforts given the sheer volume of payments it processes each year.
The stakes are significant. Iwugo said CMS’ program integrity work generated its highest return on investment in 2025, reaching roughly 22:1 after tripling over the previous three years. Yet she also emphasized the scale of the challenge. While CMS saved nearly $42 billion last year through its program integrity efforts, fraudsters continue to evolve, leveraging increasingly sophisticated technologies to execute more insidious schemes. Closing that gap will require CMS to move faster, rely more heavily on data, and intervene before payments leave the government, according to Iwugo. In Medicare fee-for-service alone, the agency receives roughly 4 million to 5 million claims each day and has a narrow, 14-day electronic claims payment window to distinguish legitimate reimbursement from activity that may signal fraud. Its current systems use AI-enabled risk scoring to sort incoming claims, identify high-risk submissions, and determine which claims warrant further review or immediate action.
That shift reflects a broader change in posture. Historically, CMS often paid claims first and pursued recovery after an investigation. But Iwugo noted that such a model is poorly suited to fraud schemes in which bad actors disappear before fraudulent payments can be recouped. “We really need to stop the claims before the money goes out the door,” she said.
One of CMS’ most noteworthy tools for doing that is the Fraud Defense Operations Center (FDOC), affectionately known as the “Medicare Fraud War Room.” The FDOC is a multidisciplinary forum that brings together attorneys, data analysts, investigators, and program integrity contractors from CMS, the Department of Health and Human Services Office of Inspector General, and at times, the Department of Justice. The group reviews data-driven leads and decides whether to take actions such as placing providers on prepayment review, suspending claims, or referring matters for further investigation.
The FDOC began with high-dollar, high-risk cases—often involving millions of dollars scheduled for payment within days. According to Iwugo, the meetings were initially difficult for staff because the decisions carried risk on both sides. Allowing suspicious payments to proceed could result in losses, while halting payments to legitimate providers could create serious operational and financial disruption.
But the model has now become central to the CMS fraud prevention strategy. Iwugo said that the FDOC, which has grown from a small group of roughly a dozen participants to as many as 40, helped suspend about $2 billion in potentially fraudulent payments during its first year alone.
The agency now brings a similar approach to the Medicaid program with the recent creation of the Medicaid Fraud War Room, though Iwugo noted that this war room has a different design because states share responsibility for program administration and enforcement.
She said that some states, including Ohio and New York, have already begun standing up their own Medicaid forums based on the CMS model. That approach allows states to use their own authorities while benefiting from CMS’s experience with identifying suspicious patterns and scaling effective interventions.
Today, the AI models CMS is using can flag high-risk claims and help package data-driven leads for human review. According to Iwugo, the next step is to move toward agentic AI that can recommend specific actions based on CMS policy, prior enforcement decisions, provider history, and expected outcomes.
In that future state, AI wouldn’t simply identify risk; it would help prioritize the highest-value cases, explain why a specific action is recommended, and show what happened when similar actions were taken in the past. Human judgment would remain essential, though CMS staff would be equipped with faster, more consistent decision support to manage a growing volume of suspicious activity.
Iwugo also emphasized that program integrity isn’t only about stopping claims after they’re submitted. CMS wants to strengthen the system’s front end by preventing bad actors from enrolling as providers in the first place. Current regulations limit the circumstances under which CMS can deny enrollment, but Iwugo said the agency is hoping to broaden its authority so it can respond to fraud schemes as they evolve.
“We've been able to take much bigger risks,” she said. “In the past, we were asked to only take action when we were absolutely sure that it was fraud. ‘Absolutely sure’ usually means there's a lengthy investigation, you've talked to beneficiaries, and you've requested medical records—and that takes forever. By the time we've done that, that money is long gone.”
That more aggressive posture could raise concerns for legitimate providers that may be caught in the net, but the agency has processes in place for providers to resubmit claims, appeal determinations, and provide evidence when they believe an action was taken in error. Iwugo said her team moves quickly to restore payments when legitimate providers are unintentionally affected.
CMS isn’t the only agency using AI to fight fraud. Program integrity is becoming more predictive, collaborative, and prioritized across the federal government. Success will depend on agencies’ legal authority, ability to align AI-enabled detection, and partnerships with states, contractors, law enforcement, and the private sector.
Guidehouse is a global AI-led professional services firm delivering advisory, technology, and managed services to the commercial and government sectors. With an integrated business technology approach, Guidehouse drives efficiency and resilience in the healthcare, financial services, energy, infrastructure, and national security markets.