Monthly OIG checks screen a healthcare workforce against federal and state exclusion databases to confirm nobody on the payroll is barred from federal healthcare programs.
Underneath the compliance framing, this is a data problem. It involves reconciling a changing roster against several government databases that update on different schedules, in different formats, with identifiers that rarely match cleanly, and producing a record of the whole exercise that survives audit.
This guide covers which sources to check and how they differ, where the monthly cadence actually comes from and how firmly, what the exposure looks like, and how the process is automated in practice through identity matching, recurring monitoring, system integration and digital audit trails.
OIG checks are recurring screenings of employees, contractors, vendors, and other individuals or entities against federal healthcare exclusion databases. The purpose is to identify excluded parties whose work could result in claims being submitted to federally funded healthcare programs.
What Monthly OIG Screening Actually Covers
Monthly OIG checks are the recurring process of screening everyone connected to billable services against databases that record healthcare exclusions and related sanctions.
An OIG exclusion is a final administrative sanction barring an individual or entity from Medicare, Medicaid, CHIP and any other federally funded health program, imposed under section 1128 of the Social Security Act. Federal programs cannot pay for items or services furnished by an excluded party.
Monthly screening is the recurring process of checking everyone connected to billable services against the databases recording those sanctions. The OIG publishes its exclusions on the List of Excluded Individuals and Entities, which it refreshes monthly.
The obligation extends past direct billers. The OIG's Updated Special Advisory Bulletin on the Effect of Exclusion, published in May 2013, states that the payment prohibition applies to items or services furnished by an excluded person, directly or indirectly, in whole or in part. Organizations conducting OIG Exclusion checks should therefore consider all individuals whose work may be connected to federally reimbursed services. The Bulletin names transportation providers, administrative services, medical equipment suppliers, billers, coders and pharmacists among those whose work can trigger liability.
That scope is what makes the problem awkward operationally. The population to be screened is larger than the clinical roster, changes constantly, and is frequently held across several systems that were never designed to talk to each other.
OIG Checks: Which Databases Should You Screen?

An effective OIG check does not necessarily mean checking only the OIG's LEIE. Depending on the organization's workforce, locations, contracts and applicable state requirements, screening may also involve SAM and state Medicaid exclusion lists.
A common error is to treat every database in the screening workflow as equivalent. They are not. Two are records of sanction. The others serve a different function.
Primary Exclusion and Debarment Databases
OIG LEIE. The federal exclusion list maintained by HHS, available at exclusions.oig.hhs.gov. Updated monthly. Records exclusions for healthcare fraud, patient abuse or neglect, license revocation and kickback schemes. This is the authoritative source for federal healthcare exclusions, and the OIG recommends relying on it over other databases for that purpose.
GSA/SAM. The General Services Administration's System for Award Management at sam.gov. Records government-wide debarments from federal contracting rather than healthcare-specific exclusions. Overlapping but not identical: a party can be debarred from federal contracting without being excluded from federal healthcare programs, and the reverse also occurs.
State Medicaid exclusion lists. Most states maintain their own, and these are the most common blind spot. A person excluded from one state's Medicaid programme does not necessarily appear on the federal LEIE. Technically these are the hardest sources to work with: there is no common format, no common update schedule, no API in most cases, and several are published as downloadable files rather than searchable databases.
Supplemental Verification Sources
Other sources appear in screening workflows without being exclusion databases, and treating them as equivalent produces confused records.
SSA Death Master File. A record of reported deaths, not sanctions. Nobody is excluded by appearing on it. Its function in a screening workflow is identity verification, flagging where an identifier on a roster may be associated with a deceased person, which can indicate a data quality problem or, occasionally, identity misuse. Useful as a supplementary check. Not a substitute for an exclusion search.
Licensure and credentialing data. State licensing board records and the National Practitioner Data Bank sit alongside exclusion screening in most credentialing workflows without forming part of the exclusion check itself.
Where the Monthly Cadence Comes From
This is frequently stated more firmly than the underlying authority supports, so it is worth separating what is mandated from what is recommended and what is contractual.
No federal statute or regulation requires providers to screen their own workforce monthly. The OIG has acknowledged as much. What exists is a strong and consistently repeated recommendation.
The OIG recommends it. The 2013 Updated Special Advisory Bulletin states that because the LEIE is updated monthly, screening employees and contractors each month best minimises potential overpayment and civil money penalty liability. That is guidance rather than a rule, but it establishes the standard the OIG will measure against.
CMS regulations require states to screen providers monthly. The 2011 final rule at 42 CFR 455.436 requires state Medicaid agencies to check enrolled providers against exclusion databases monthly. Note what this does and does not cover: it obliges states to screen the providers they enrol. CMS clarified in response to comments that the regulation does not mandate states to require their Medicaid providers to screen those providers' own employees and contractors monthly.
CMS has recommended that states impose it on providers. State Medicaid Director Letters #08-003 of June 2008 and #09-001 of January 2009 advised states to require providers to screen employees and contractors monthly. Many states have adopted that as a programme requirement, which is why monthly screening is a genuine obligation for a large share of providers. It arrives through state programme rules or provider agreements rather than federal regulation, and the specifics vary by state.
Medicare Advantage and Part D contracts typically require it. Where monthly screening is contractually required, the obligation is real and enforceable through the contract, not through federal healthcare regulation.
The practical argument sits underneath all of this and is the simplest. The LEIE republishes monthly. Any check older than 30 days runs against a stale dataset, and exclusion status changes without notice to the employer, so the interval between checks is the period carrying unmeasured risk.
What Non-Compliance Costs
Penalty figures in older guidance are significantly out of date. The frequently quoted $10,000 per claim predates the Bipartisan Budget Act of 2018, which doubled the statutory amount before annual inflation adjustments pushed it higher.
- Civil money penalties. Roughly $25,000 per item or service claimed, per violation occasion, under the current HHS inflation adjustment. The figure is adjusted annually, so confirm the current amount against the applicable Federal Register notice rather than a secondary source.
- Overpayment liability. Repayment of every federal payment connected to the excluded party, irrespective of knowledge.
- False Claims Act exposure. Additional liability where claims involve services furnished, ordered or prescribed by an excluded person.
- Programme consequences. Suspension or revocation of billing privileges, and mandatory corrective action.
The distinction worth understanding is between the two liabilities. Overpayment repayment applies regardless of whether the employer knew about the exclusion. Civil money penalty liability under section 1128A generally requires that the provider knew or should have known. Consistent documented screening is what establishes which side of that line an organisation sits on.
The Technology Problem Underneath the Compliance Problem

Most published guidance describes what to check and how often. Rather less addresses why doing it manually stops working at a certain scale, which is the part that determines what an organisation actually implements.
Identity Matching Is the Hard Part
Exclusion databases hold names, and names are poor identifiers. A search for a common surname returns results that may or may not be the person on your roster, and the databases vary in what secondary identifiers they carry. The LEIE includes date of birth and address data for many entries. Several state lists carry little beyond a name and a date.
This produces two failure modes. False positives consume staff time investigating people who are not excluded. False negatives occur where a genuine match is missed because the name is recorded differently, a maiden name is in use, or a middle initial is absent.
Automated screening addresses this through probabilistic matching across multiple identifiers, comparing name variants, date of birth, National Provider Identifier and licence numbers to produce a confidence score rather than a binary result. The resolution step is where screening systems differ most: some surface a potential match and stop, leaving the judgment and the documentation to the customer, while others carry the investigation through to a documented conclusion.
Recurring Monitoring Versus Periodic Search
A monthly search is a point-in-time query. Continuous monitoring holds the roster as a persistent record and re-evaluates it whenever a source database updates, which surfaces changes closer to when they occur.
The distinction matters most for the sources that do not update on the LEIE's monthly cycle. State lists and SAM update on their own schedules, and a system checking everything once a month against all of them is, by definition, later than it needs to be on some of them.
Integration With HRIS and Credentialing Systems
The most common failure point in exclusion screening is not the search. It is the roster.
A screening list maintained manually drifts out of date within weeks. New hires get added late, leavers stay on for months, and contractor populations are frequently not captured at all because they sit outside the HR system. Every one of those gaps is an unscreened person connected to billable services.
Integration with an HRIS or applicant tracking system closes that gap by making the roster a live feed rather than a periodically updated spreadsheet. Where a screening platform offers an API or automated file transfer, new starters enter the screening population on their start date without anyone remembering to add them, and leavers exit it automatically.
For organisations with credentialing systems, the same integration argument applies to provider data, where exclusion status sits alongside licensure and certification as a recurring verification requirement.
The Digital Audit Trail
Screening that cannot be evidenced is, to an auditor, screening that did not happen.
A complete record covers who was screened, which databases were checked, on what date, what was found, and how each potential match was resolved. Producing that manually across a roster of any size is substantial work, and it is work that has to be repeated every month.
Automated systems generate it as a by-product of running the check, with timestamped records and exportable reports. When evaluating any screening approach, the question worth asking is whether the audit record is produced automatically or assembled afterwards, because that difference is usually larger than the cost of the software.
How to Run Monthly Checks Step by Step
Build and maintain the screening roster. List every employee, contractor, vendor and volunteer connected to federally reimbursed services. Automate the update where possible, because a roster maintained by hand is the most common point of failure.
- Collect complete identifiers. Full legal name and known aliases, date of birth, National Provider Identifier and professional licence numbers where applicable. Thin identifiers generate false positives that then require manual resolution.
- Search the applicable databases. The LEIE and SAM are free to search at exclusions.oig.hhs.gov and sam.gov. State lists sit on individual state Medicaid agency sites, each with its own format and search behaviour.
- Resolve every potential match. Compare identifiers across multiple data points, request supporting documentation where needed, and document the reasoning behind the conclusion. An unresolved potential match is worse than no check at all, because it evidences notice.
- Document the cycle. Record who was screened, which databases were checked, the date, what was found and how each match was resolved. This is what an auditor asks for.
- Act immediately on a confirmed match. Remove the individual from all federally reimbursed duties, then take legal or compliance advice on disclosure and repayment obligations. The OIG operates a Self-Disclosure Protocol for this purpose.
Choosing an Approach

Three broad approaches exist, and the right one depends on roster size, how many state lists apply, and how much of the resolution and documentation work an organisation wants to own.
Direct government search. Manual checks against the LEIE and SAM cost nothing and are entirely defensible for a small roster. The limits are scope and labour: two federal sources, no state coverage, and every match investigation and record falls to internal staff. Workable for a roster of roughly twenty with someone reliably performing it monthly.
Managed screening services. A provider runs the searches and resolves the matches, covering the LEIE, GSA/SAM, available state Medicaid lists and supplementary identity sources. Exclusion Screening is one such provider, with an emphasis on resolution, meaning identity is confirmed through multiple data points and documented logic rather than a potential match being passed back unexamined.
Screening and monitoring platforms. Software-led options automate continuous monitoring at scale, aggregating exclusion, debarment and sanction data from a wide range of federal and state sources, and delivering results through APIs, secure file transfer or web platforms. Some integrate with HRIS, applicant tracking or credentialing systems so the roster stays current without manual maintenance. Others pair exclusion monitoring with licence verification for combined compliance and credentialing workflows.
The question that separates all of them is what happens to a potential match. Some surface it and stop, leaving investigation and judgment with the customer. Others carry it through to a documented conclusion. That single distinction determines how much staff time monthly screening actually consumes, much like the systems handling HIPAA-compliant patient communication either absorb administrative load or quietly add to it. That difference is rarely visible on a feature comparison.
Documentation and the Audit Trail
Keep a record for every cycle covering the individual or entity searched, the identifiers used, the databases checked, the search date, results and resolution steps for any potential match. Retain it in a form producible on demand.
If a solution cannot generate that record automatically, price in the staff hours required to build it manually. That cost is usually larger than the subscription it appeared to save.
FAQs about monthly OIG checks
Q1. How often do I actually need to run OIG checks?
Before hiring or beginning a business relationship, then monthly thereafter. Monthly is required by all state Medicaid programs, Medicare Advantage plans and Medicaid managed care organizations, and matches the LEIE update cycle.
Q2. Can I just use the free OIG website?
Yes, and it is legitimate. It covers the LEIE, and SAM.gov alongside it covers federal debarments. It does not cover state Medicaid exclusion lists, and every potential match is yours to resolve and document.
Q3. Who exactly do I have to screen?
Every employee, vendor, and contractor providing items or services payable by federal healthcare programs, directly or indirectly.
The OIG has stated that penalty liability is greatest for those providing items or services integral to patient care.
Q4. What happens if someone on my staff appears on the list?
Remove them from all federally reimbursed duties immediately and consult legal or compliance counsel on disclosure and repayment. Penalties reach $25,595 per item or service alongside repayment of every affected claim.