Compliance

NEMT Compliance Program in 2027: The Seven Elements Sized for a Small Company

Three clipboards holding printed checklists, with red pens laid across them, on dark pavement
Photo: United States Marine Corps, Wikimedia Commons, Public domain

A NEMT compliance program is the written system that keeps your billing, drivers, and records inside Medicaid rules. HHS OIG guidance sets seven elements: written policies, a compliance leader, training, a way to raise concerns, discipline, risk checks and audits, and fixing problems. A small company can run all seven with one named contact, monthly exclusion checks, a yearly audit, and a calendar.

  • OIG's seven elements are voluntary, but brokers write parts of them into contracts, and New York requires a full program at $1 million in Medicaid in any 12 months.
  • A five-van company can name one compliance contact who does not do the billing and reports to the owner at least every quarter.
  • Screen every owner, employee, driver, and contractor against the OIG, SAM, and state exclusion lists before hiring and every month.
  • Assess your risks and audit a sample of claims at least once a year, and return any overpayment within 60 days.
  • Put every task on a yearly calendar so screening, training, audits, and policy reviews happen on time.

A compliance program is the set of routines that stops honest mistakes from turning into overpayments, and overpayments from turning into fraud cases. The HHS Office of Inspector General (OIG) describes seven elements for every health care business. This guide cuts them down to what a company with one office and a few vans can run, and ends with a yearly calendar.

Is a compliance program required for NEMT?

For most small NEMT companies, no general federal rule requires a full compliance program as of September 2026. OIG’s General Compliance Program Guidance (November 2023) says it is voluntary and binds no one. Pieces of a program are required, though, depending on your size, your state, and your contracts.

Rule Who it reaches What it requires
Social Security Act 1902(a)(87) Every NEMT provider and driver paid by Medicaid, except public transit Provider and drivers not excluded, a valid license for each driver, a process to address state drug law violations, and a process to disclose each driver’s driving history to the state
Social Security Act 1902(a)(68), from the Deficit Reduction Act of 2005 Any entity that receives or makes at least $5,000,000 a year in Medicaid payments Written policies for staff and contractors on the False Claims Act, whistleblower protections, and preventing fraud, repeated in any employee handbook
New York Social Services Law 363-d and 18 NYCRR Part 521 New York providers that claim or receive at least $1,000,000 from Medicaid in any 12 months in a row, directly or indirectly, such as through a managed care plan A full compliance program with eight elements, attested every year on the anniversary of Medicaid enrollment
Medicaid managed care, 42 CFR 438.608 Health plans, and through them their network providers A way for providers to report and return overpayments within 60 calendar days with a written reason. Plans also check by sampling that billed services were received.
Broker agreements Every provider that signs one See the broker examples below

Brokers write parts of a program into their contracts. MTM Health’s standard agreement, in the January 1, 2023 version Pennsylvania posts, requires you to take part in quality and compliance programs (section 2.T) and to follow the False Claims Act, the Anti-Kickback Statute, and the Deficit Reduction Act of 2005 (section 2.U). Driver training must include fraud, waste, and abuse and HIPAA (section 5.B), and no one on the OIG or federal exclusion lists may drive or attend (section 5.E). Modivcare’s 2025 compliance attestation has you certify that owners and drivers completed its code of conduct and compliance training for the calendar year. It also requires a conflict of interest policy, or following the one in Modivcare’s code, and training records kept for at least 10 years.

One federal change could come later. The Affordable Care Act makes a compliance program a condition of enrolling in Medicare and Medicaid, with state Medicaid programs following suit (42 U.S.C. 1395cc(j)(9) and 1396a(kk)(5)). That duty starts only on a date HHS sets for each type of provider, using core elements it writes with OIG.

OIG is also writing guides for single industries. As of September 2026 it has published them for nursing facilities (November 20, 2024) and Medicare Advantage plans (February 3, 2026), but not for NEMT. Until one exists, the general guidance applies, and OIG’s 2003 guidance for ambulance suppliers, now in its archive, is the closest industry guide for a transportation company.

OIG has two NEMT reviews under way as of September 2026. It announced a targeted review of Medicaid NEMT billing on October 15, 2025, using “key indicators of concerning billing,” and a new audit series of state NEMT payments on May 28, 2026. See the OIG NEMT reviews.

The seven elements, cut down to a five-van company

OIG’s guidance has a section for small entities. It keeps all seven elements but lets a small company meet them with less staff and paperwork.

Element What OIG suggests for a small company At a five-van NEMT company
1. Written policies and procedures Policies and training on doing the work within program rules. Templates are fine if you edit them to fit. Review at least once a year. A short code of conduct and short policies on billing, trip records, screening, gifts, and reporting, signed by everyone
2. Compliance leadership One compliance contact if you cannot support a compliance officer. Not the biller where possible. Reports to the owner at least quarterly. The office manager or lead dispatcher, named in writing, with a quarterly meeting with the owner
3. Training Training at hire, with updates and reminders. The general guidance says everyone at least once a year. Compliance training at hire and every year, plus each broker’s required courses
4. Lines of communication An open door, a written duty to report in good faith, no retaliation, and the OIG hotline posted where anonymity is not possible A notice in the drivers’ room with the contact’s phone, the owner’s phone, and 1-800-HHS-TIPS
5. Enforcing standards Discipline set before violations happen, with room to ask questions and admit mistakes A written, stepped discipline policy. Falsified trip records are grounds for firing.
6. Risk assessment, auditing, and monitoring A risk assessment and an audit at least once a year, and routine checks of exclusion lists and licenses A January risk list, a yearly claims audit, and monthly exclusion, license, and trip checks
7. Responding and correcting Someone who decides whether a violation happened and what to do: a corrective action plan, repayment, a report, or a disclosure to OIG Stop, find the scope, refund within 60 days, fix the cause, and write it down

1. Written policies and a code of conduct

OIG describes a code of conduct as the document that states your commitment to follow federal and state law and the ethical standards everyone who works for you must meet. Behind it sit policies on how the program runs and how you avoid your biggest risks. OIG says every organization should have a written policy on exclusion screening that names who screens, how possible matches are checked, and what happens after a match.

Write policies people will actually read. OIG says they should be easy to find and easy to understand, translated where needed and written at a fitting reading level. Review every policy at least once a year. For a NEMT company, the core list is:

  • Billing from trip records. Bill only trips with a complete trip log, loaded miles only, and never a no-show as a trip. CMS’s NEMT booklet for providers (April 2016) calls billing loaded miles for a no-show a common form of NEMT fraud.
  • Level of service. Bill the level the rider was approved for, not the vehicle you sent.
  • Driver qualifications. The four federal minimums in section 1902(a)(87), plus your state’s and brokers’ rules.
  • Exclusion screening. Who checks, which lists, how often, and what to do on a match.
  • Gifts and referrals. No payments for referrals. OIG treats a gift to a Medicaid rider as nominal only at $15 or less per item and $75 or less a year, and never cash or a cash equivalent (policy statement of December 7, 2016). See anti-kickback rules for NEMT.
  • Conflicts of interest, which Modivcare requires.
  • Reporting concerns and no retaliation.
  • Refunds and record keeping.

The NEMT policies and procedures guide covers the operating policies that sit alongside these.

2. A compliance contact

A small company that cannot support a compliance officer, full-time or part-time, should name one compliance contact, OIG says. That person makes sure the compliance work gets done. They should not do the company’s legal work and, whenever possible, should not bill, code, or submit claims. Without a board, the contact reports to the owner at least quarterly. The owner remains ultimately responsible.

The reason for keeping billing separate is simple: the person who checks the claims should not be the person who sent them. If you are the owner and the only office worker, the check can come from an outside reviewer instead, such as a billing consultant who audits a sample each year.

New York’s rules go further for providers at the $1,000,000 threshold. They require a compliance officer who reports at least quarterly to the chief executive, the governing body, and a compliance committee, plus a yearly review of policies (18 NYCRR 521-1.4). See the New York state guide.

3. Training

OIG recommends that everyone receive compliance training at least once a year. It should cover your commitment to the rules, the fraud and abuse laws such as the False Claims Act and the Anti-Kickback Statute, and how your program works. A small company can deliver it at a staff meeting, by email, or through posted notices, as long as new staff get it when they join and everyone gets reminders.

Broker requirements set the floor. MTM Health requires fraud, waste, and abuse and HIPAA training in every driver program. Modivcare’s 2025 attestation lists its code of conduct and a compliance course covering general compliance, fraud, waste, and abuse, HIPAA, the ADA, health and safety, and cultural competency, finished within 30 days of hire. CMS’s booklet adds a point every driver should hear: document accurately, and never embellish a trip record. Record who attended with the driver training log, and see NEMT driver training.

4. Ways to raise concerns

A formal hotline may not fit a small company, OIG says, but staff must know you are committed to compliance and to no retaliation. Its suggestions for small entities include:

  • An open door policy to raise concerns with the compliance contact or the owner.
  • A written rule that staff report conduct they believe in good faith is wrong, improper, or fraudulent.
  • A simple process for handling each report.
  • An anonymous drop box where that is practical.
  • A written promise of no retribution for good faith reports.
  • A notice with the OIG hotline, 1-800-HHS-TIPS, posted where reports cannot stay anonymous.

5. Discipline and incentives

Set out the consequences before anything goes wrong. OIG says discipline should be in place ahead of violations and flexible enough that staff can still ask questions and admit mistakes. You may also make failing to report a violation a disciplinable offense. CMS’s booklet advises written policies that make falsifying transportation records grounds for discipline up to termination.

6. Risk assessment, audits, and monitoring

OIG asks small entities to assess their compliance risks at least once a year, and says it does not have to be complicated. Review your own data, such as claim denials and complaints. Read the OIG Work Plan. Brainstorm at a staff meeting. Then choose how to handle the top risks: an audit, ongoing monitoring, or a process change.

Run at least one audit a year, picking claims based on the risk assessment. If it turns up a pattern, expand the audit or get outside help. Between audits, watch warning signs such as a jump in claim rejections or an unusual change in the codes you bill. The Medicaid audit guide has a monthly self-audit you can adopt.

NEMT risk What to check Source
Rides billed without complete records Match a sample of claims to trip logs and signatures CMS NEMT booklet
Rides that never happened Call a few riders and appointment locations to confirm arrival CMS NEMT booklet
Miles billed without the rider aboard Compare billed miles with odometer or GPS records CMS NEMT booklet
No-shows billed as trips Confirm every no-show has no trip claim CMS NEMT booklet
Excluded staff Screen everyone monthly against the OIG, SAM, and state lists OIG bulletin, May 8, 2013
Unlicensed or unqualified drivers Check licenses and driving history under your written process 1902(a)(87)
Gifts and referral payments Review the gift log and any payments to referral sources OIG policy statement, December 7, 2016
Kept overpayments Confirm each refund went back within 60 days 42 U.S.C. 1320a-7k(d)
Rider privacy Review your HIPAA risk analysis HIPAA for NEMT

The NEMT fraud guide shows the schemes investigators find most often, which is a good starting list for your own risk assessment.

7. Responding to problems

Expect the program to find things. OIG says a small company should be ready to name someone, whether the compliance contact or the owner, to decide whether a violation happened and what to do. The options include a corrective action plan, returning overpayments, a report to the agency that paid, or a disclosure to OIG. A corrective action plan can change a policy or process, retrain staff, revise the training plan, and apply consequences to the people involved.

  1. Stop billing the affected trips until you know what went wrong.
  2. Find the scope: the dates, drivers, and claims involved.
  3. Return overpayments within 60 days after you identify them, with a written reason (42 U.S.C. 1320a-7k(d)). An overpayment kept past that deadline becomes a False Claims Act obligation, and False Claims Act penalties run $14,308 to $28,619 per claim plus three times the government’s damages (penalties assessed after July 3, 2025, under 28 CFR 85.5). Managed care plans must give network providers a way to return it within 60 calendar days (42 CFR 438.608). See the 60-day overpayment rule.
  4. Get legal advice if it looks like fraud. OIG’s Self-Disclosure Protocol (amended November 8, 2021) generally settles with a minimum multiplier of 1.5 times single damages, and a minimum settlement of $20,000, or $100,000 for kickbacks.
  5. Fix the cause and write down what you changed.

Exclusion screening, the check that matters most

An excluded person cannot do any work Medicaid pays for at your company. OIG’s Special Advisory Bulletin of May 8, 2013 says excluded people may not provide transportation paid for by a federal health care program, and gives ambulance drivers and ambulance dispatchers as examples. They also may not do administrative or management work, even when it is not billed separately. Federal law requires that no NEMT provider or driver paid by Medicaid be excluded (Social Security Act 1902(a)(87)), and CMS’s coverage guide says transportation providers must screen their employees (SMD 23-006, September 28, 2023).

How often. OIG says no statute or regulation requires providers to check its List of Excluded Individuals and Entities (LEIE). It updates the list monthly, though, so screening each month best limits your overpayment and penalty risk. CMS asked states on January 16, 2009 to require providers to check monthly (SMDL 09-001).

Which lists. Check three places:

  • The OIG LEIE.
  • The exclusions on SAM.gov, which CMS’s NEMT booklet tells providers to check as well.
  • The Medicaid exclusion list of each state you bill, if it keeps one, such as New York’s OMIG list. OIG’s guidance calls for screening against every state Medicaid exclusion list that applies to you.

Whom. Screen owners, managers, office staff, drivers, attendants, and contractors whose work Medicaid pays for, such as a billing company. You may rely on a contractor’s own screening, but OIG says to confirm it and keep copies, because the risk stays with you. See the OIG exclusion list and SAM exclusions.

Proof. OIG says to keep a record of each name search, such as a printed screenshot of the results. The exclusion screening log keeps one line per person per month.

A possible match. Confirm it before acting. The downloadable LEIE file has no Social Security or employer numbers, so verify through OIG’s online search. If the match is real:

  1. Take the person off all Medicaid work at once.
  2. Work out what Medicaid paid for their services, since those payments may be overpayments.
  3. Screen every current employee and contractor. OIG’s Self-Disclosure Protocol requires this before a disclosure and asks you to disclose all excluded people at once.
  4. Ask an attorney whether to self-disclose. The disclosure describes the person’s duties, their dates of work, your screening process, what broke down, and how you fixed it.

The cost of skipping this is real. When you employ or contract with an excluded person, OIG can impose a civil money penalty of up to $25,595 for each item or service that person furnished, such as each ride, plus an assessment of up to three times the amount claimed (42 CFR 1003.210, with the HHS inflation adjustment for penalties assessed on or after January 28, 2026).

A yearly compliance calendar for a small NEMT company

Fixed dates keep the program running when the business gets busy. The months below are an example. Pick your own, put them on the office calendar, and have the compliance contact mark each task done.

When What to do Rule or guidance
At every hire Screen before the first day, check the license and driving record, and give compliance training 1902(a)(87); OIG bulletin; Modivcare (training within 30 days)
Every month Screen everyone against the LEIE, SAM, and state lists, and save the results OIG bulletin; SMDL 09-001
Every month Match a sample of claims to trip logs, signatures, miles, and level of service CMS NEMT booklet
Every month Call a few riders or clinics to confirm rides happened CMS NEMT booklet
Every month Read broker and state notices and update any policy they change OIG guidance
Every quarter Compliance contact reports to the owner: screening, audit results, concerns, refunds, open fixes OIG guidance (at least quarterly)
Every quarter Check the refund log and the gift log 42 U.S.C. 1320a-7k(d); OIG policy statement
January Risk assessment, and a written plan for the year’s audit and training OIG guidance (at least yearly)
February Yearly compliance training, and everyone signs the code of conduct again OIG guidance; Modivcare (each calendar year)
April Yearly claims audit, aimed at the top risks from January OIG guidance (at least yearly)
June Review every policy and update the effective dates OIG guidance (at least yearly)
September Review your HIPAA risk analysis 45 CFR 164.308(a)(1)
Once a year for each driver Criminal background check and a driving record covering the past 3 years, for MTM Health drivers MTM agreement, section 5.C
Enrollment anniversary, New York providers at $1 million Attest to your compliance program on the yearly certification statement NY OMIG
November Check how well each element worked this year, and plan changes OIG guidance (periodic effectiveness review)

The records your program should produce

Keep proof of every step, because brokers and auditors ask for it. MTM Health’s agreement, for example, lets MTM and government officials inspect and copy your records, unannounced (section 2.T). Keep these, dated and filed where the compliance contact can find them:

  • The code of conduct and every policy, with the dates each version was in effect.
  • Signed acknowledgments and training rosters.
  • Monthly screening results for every person.
  • Audit reports, risk assessments, and corrective action plans.
  • Reports of concerns and how each was resolved, using a complaint log or a separate compliance log.
  • The refund log, with the date each overpayment was identified and returned.
  • The quarterly reports to the owner.

Keep them at least as long as your longest rule. HIPAA requires covered entities to keep required documentation for 6 years from creation or from when it was last in effect (45 CFR 164.530(j)). MTM Health’s standard agreement requires full records for 10 years (section 2.S), and Modivcare wants training records for at least 10 years. See NEMT record retention.

Frequently asked questions

Is a compliance program required for a NEMT company?

Not by a general federal rule for small companies as of September 2026. OIG's General Compliance Program Guidance (November 2023) is voluntary. Specific rules still apply: companies paid $5 million or more a year by Medicaid need written False Claims Act policies, New York requires a full program at $1 million in any 12 months, and every NEMT provider must meet the federal driver and exclusion minimums. Brokers such as MTM Health and Modivcare add their own requirements.

Who should be the compliance officer at a small NEMT company?

OIG says a small company that cannot support a compliance officer can name one compliance contact instead. Where possible, that person should not bill, code, or submit claims, and should not handle the company's legal work. The contact reports to the owner at least quarterly, and the owner stays ultimately responsible. An office manager or lead dispatcher who does not do the billing can fit the role.

How often should a NEMT company check the OIG exclusion list?

Before you hire anyone, then every month. OIG says no statute or regulation requires providers to check its list, but it updates the list monthly, so monthly screening best limits your risk. CMS asked states in 2009 to require monthly checks, and federal law requires that no NEMT provider or driver paid by Medicaid be excluded. Check SAM.gov and your state's Medicaid exclusion list too, and keep a record of each search.

What training does a NEMT compliance program need?

OIG recommends training at hire and at least once a year on the compliance program and the fraud and abuse laws. Brokers name specific courses. MTM Health's standard agreement requires fraud, waste, and abuse training and HIPAA training in every driver program. Modivcare's 2025 attestation requires owners and drivers to finish its compliance training each calendar year, with new employees done within 30 days of hire.

What do I do if I find a billing mistake?

Stop billing the affected trips, work out which claims it touched, and return the overpayment within 60 days after you identify it, with a written reason (42 U.S.C. 1320a-7k(d)). Use the refund process of whoever paid the claim: the state, the broker, or the health plan. If the problem looks like fraud, such as falsified trip logs, talk to a health care attorney about OIG's Self-Disclosure Protocol.

What happens if I employ an excluded driver?

Medicaid pays nothing for services an excluded person furnishes, including driving and dispatching, so those payments can become overpayments. OIG can also impose a civil money penalty of up to $25,595 for each item or service the person furnished, such as each ride, plus up to three times the amount claimed (penalties assessed on or after January 28, 2026). Take the person off all Medicaid work, screen everyone else, and ask an attorney whether to self-disclose.

Official resources

One email a month

Broker changes, new state rules, and new guides. No spam.

Get the newsletter