
OIG Exclusion Screening: A Compliance Playbook for 2026
OIG exclusion screening is the process of checking the Office of Inspector General’s List of Excluded Individuals and Entities (LEIE) so your organization never employs, contracts with, or pays someone barred from Federal health care programs. The minimum defensible policy: screen every covered person at onboarding, then again regularly for as long as they touch federally reimbursed work.
If you manage compliance for a public safety agency, EMS department, or any organization billing Medicare, Medicaid, or another federal health program, here is what to do this week:
- Pull a current roster of anyone hired or contracted in the last 30 days and run each name through the LEIE.
- Verify any potential match using Social Security Number or Employer Identification Number before taking action, since name matches alone produce false positives.
- Log the search date, results, and verification steps for every person checked, even when the result is clean.
Pro Tip: Screening at hire and forgetting about it is the single most common gap OIG auditors flag. An exclusion can happen to someone already on your payroll, and the Special Advisory Bulletin treats monthly rechecking as the standard that limits Civil Monetary Penalty exposure.
Key Takeaways
A defensible OIG exclusion screening program requires monthly LEIE checks, secondary identity verification for every match, and documented audit trails covering employees, contractors, and vendors alike.
| Point | Details |
|---|---|
| Screening frequency | Check the LEIE at onboarding and monthly thereafter to align with OIG’s own update cycle. |
| Scope covers more than staff | Include contractors, temp workers, volunteers, and owners or board members tied to billing. |
| Verification is mandatory | Confirm any potential match with SSN, EIN, or NPI before acting on it. |
| Vendor flow-downs close the gap | Require attestations, audit rights, and documentation from every staffing agency and contractor. |
| OMNI Intel supports the process | Automates monthly screening, verification, and audit logging for public safety and health-adjacent agencies. |
Where to verify OIG guidance directly
For primary confirmation of anything in this guide, consult OIG’s exclusions database for the current LEIE, the LEIE Quick Tips for search mechanics, and the Special Advisory Bulletin for the underlying screening rationale and CMP exposure. Each is the agency’s own authoritative statement on the topic, not a third-party summary.
Table of Contents
- What Is the OIG Exclusion List and Why Does It Matter?
- Who Needs OIG Screening and How Often
- How Do You Run an OIG Exclusion Screening Process?
- Verifying Matches and Building an Audit Trail
- Screening Contractors, Staffing Agencies, and Vendors
- What Happens if an Excluded Person Is Discovered?
- Mandatory vs. Permissive Exclusions: What Is the Difference?
- The Legal Framework Behind OIG Exclusion Authority
- What Compliance Failures Actually Look Like
- How OMNI Intel Operationalizes Exclusion Screening
- OMNI Intel Gives Your Agency an Auditable Screening Program
- Sources
- FAQ
What Is the OIG Exclusion List and Why Does It Matter?
The OIG’s authority to exclude individuals and entities comes from sections 1128 and 1156 of the Social Security Act, and the consequence is blunt: no Federal health care program can pay for any item or service furnished, ordered, or prescribed by an excluded person. That prohibition applies even to services performed by an excluded individual who is not billing directly, such as a nurse, technician, or administrative staffer whose work supports a billed claim.
This is why OIG exclusion screening exists as a distinct compliance function rather than a footnote in a background check. A clean criminal history check tells you nothing about program exclusion status. The LEIE is a separate, purpose-built registry that OIG updates monthly, and it is the tool that tells you whether continuing to employ or pay someone would trigger a payment prohibition.
A common point of confusion is the relationship between the LEIE and the System for Award Management (SAM), the government-wide exclusion and debarment database. They overlap, but they are not interchangeable. OIG’s own guidance states that the LEIE provides greater detail about excluded individuals than SAM does and should serve as the primary source for health care exclusion screening. SAM.gov casts a wider net across all federal procurement and grant exclusions, which makes it useful for government contracting broadly, as explained in this overview of navigating SAM.gov exclusions. But for anyone whose work touches federally reimbursed health care, the LEIE is the authoritative record, and OIG guidance treats it that way.
A few facts worth keeping in front of your compliance team:
- The LEIE is regularly refreshed, meaning a person clean at one time can later appear on the list following updates.
- Exclusions are not issued casually. They typically follow formal proceedings, including a Notice of Intent to Exclude and, in many cases, an administrative law judge appeal, so a listing reflects documented administrative authority, not a clerical flag.
- Payment prohibition applies to the item or service, not just to direct billing, so indirect roles are still in scope.
Who Needs OIG Screening and How Often
Scope creeps faster than most agencies expect. If your organization receives any reimbursement tied to Medicare, Medicaid, or another Federal health care program, your screening obligation extends beyond just the people who submit claims.
At minimum, your screening population should include:
- All employees whose duties touch patient care, billing, coding, or supervision of those functions.
- Contractors and temporary staff, including per diem clinicians, agency nurses, and locum providers.
- Volunteers working in any capacity connected to reimbursable services.
- Owners, officers, and board members who influence billing decisions or program participation, since OIG’s exclusion authority extends to individuals with ownership or control interests.
- Subcontractors engaged by your primary contractors, if their work is integral to billed services.
Why monthly? Because the LEIE itself updates monthly, and screening less often creates a documented gap during which an excluded person could remain on payroll undetected. OIG’s Special Advisory Bulletin frames monthly screening as the best practice for minimizing CMP liability, even though there is no single statutory mandate spelling out the exact interval. That distinction matters for how you defend your program: a monthly cadence is what regulators expect to see, and falling short of it weakens your “we exercised due diligence” argument if an excluded person is later discovered.
Higher-risk roles deserve tighter cycles. Anyone with signature authority over claims, anyone recently disciplined by a licensing board, or anyone flagged in a prior audit should get event-driven checks in addition to the standard monthly run.
Pro Tip: Treat every new hire, license renewal, and credentialing update as a trigger for an immediate, out-of-cycle LEIE check. Waiting for the next scheduled monthly batch to catch a new employee is exactly the kind of delay auditors zero in on.
How Do You Run an OIG Exclusion Screening Process?

A defensible OIG screening process is built the same way every time: capture the right identifiers, search the right database the right way, verify anything that looks like a match, and log every step. Here is the workflow broken into stages.

Step 1: Collect identifiers at onboarding
Before you can screen anyone properly, you need more than a name. Collect legal name, any known aliases or maiden names, date of birth, National Provider Identifier where applicable, and, where lawful and job-justified, SSN or EIN. Weak intake data is the number one cause of missed or misresolved matches later.
Step 2: Choose your search method
OIG offers three ways to interact with the LEIE, and each fits a different use case:
- LEIE Online Search works best for one-off checks and for verifying a potential match, because it allows SSN or EIN confirmation directly against a specific record.
- Downloadable Database is built for batch matching across an entire roster, but the exported file omits SSNs entirely, which means it can only get you to a preliminary name match, not a confirmed one.
- Monthly Supplement File lists new exclusions and reinstatements added since the last full file update, useful for organizations that want to check only what changed rather than rerun a full roster every time.
Step 3: Automate the recurring parts
Manually re-searching every employee’s name every 30 days does not scale past a handful of staff. Most agencies land on one of three approaches:
- Batch uploads against the downloadable LEIE file on a fixed monthly schedule.
- Scheduled automated jobs that run without manual initiation and flag exceptions for human review.
- HR or credentialing system integrations that trigger a screening event automatically whenever a new hire, contractor, or license renewal enters the system.
Whichever method you choose, the automation should produce a record, not just a result. A screening run that shows “no matches found” with no timestamp, no search parameters, and no export is functionally the same as never having run it at all if you are asked to prove due diligence months later.
- Bullet-list your exceptions separately from clean results so reviewers can see at a glance what needs human eyes.
- Route any potential match to a compliance reviewer immediately rather than batching them for end-of-month review.
Pro Tip: Build your automation to flag “possible matches” separately from “no matches,” and require a named reviewer to close out every possible match within a set number of business days. An open, unresolved match sitting in a queue for weeks is a worse audit finding than the exclusion itself.
Verifying Matches and Building an Audit Trail
A name match on the LEIE is not proof of exclusion. It is a starting point that requires secondary verification before you act. This is one of the most misunderstood steps in the entire process, and getting it wrong in either direction creates risk: acting on an unverified false positive can trigger a wrongful termination claim, while dismissing a real match without proper verification leaves an excluded person on the payroll.
The correct sequence, per OIG’s own guidance, is to confirm the match using SSN for individuals or EIN for entities through the Online Search tool. This is precisely why the downloadable database, useful as it is for batch scanning, cannot be your final word on any specific person. It lacks the SSN field needed to close the loop.
Once verification is complete, your documentation should include:
- A screenshot or exported record of the original search, including the date and parameters used.
- The verification log showing which identifier (SSN, EIN, NPI) confirmed or ruled out the match.
- Written match-resolution notes explaining the reviewer’s conclusion and any follow-up action taken.
- Attestations from contractors or staffing agencies confirming they conducted their own screening, when applicable.
OIG has been explicit that providers should maintain documentation of the initial search and any verification steps as proof of due diligence if questioned by auditors. A screening program with no paper trail is, from an auditor’s perspective, indistinguishable from no screening program at all.
Store this documentation securely given the sensitive personal identifiers involved. SSNs and dates of birth carry their own handling obligations independent of OIG requirements, so retention policies should align with your broader data security standards, not just your compliance calendar. Keep records for the duration recommended by your legal counsel, typically tied to your organization’s overall recordkeeping and audit cycle.
Screening Contractors, Staffing Agencies, and Vendors
Outsourcing a function does not outsource your liability. If a contractor, staffing agency placement, or subcontractor performs work billed to a Federal health care program, your organization remains exposed if that person turns out to be excluded, even though someone else technically employs them. OIG has specifically called out contractor and staffing agency personnel whose work is integral to patient care as a screening priority, not an afterthought.
The practical fix is contractual. Build these clauses into every vendor and staffing agreement:
- A written attestation that the vendor conducts monthly LEIE screening on every individual assigned to your account.
- A right-to-audit clause allowing you to request and inspect the vendor’s screening logs on demand, not just at contract renewal.
- Indemnification language that shifts financial responsibility back to the vendor if a failure to screen results in penalties against your organization.
Contract language alone is not enough if you never check whether the vendor is actually complying. Validate the relationship periodically by requesting sample screening reports, reviewing a vendor’s documented process against your own standards, and conducting occasional spot audits rather than relying entirely on the vendor’s word. A signed attestation with no supporting evidence is a weak substitute for an actual log.
Pro Tip: Ask new vendors for a sample of their screening documentation before you sign, not after. If a staffing agency cannot produce a clean example of a completed screening record during the sales process, that is a preview of what their ongoing compliance will look like.
What Happens if an Excluded Person Is Discovered?
Discovering an excluded employee or contractor after the fact triggers real financial and legal exposure, and how fast you act shapes how much of that exposure you can limit.
The consequences can include Civil Monetary Penalties, overpayment recoupment demands, potential False Claims Act liability if claims were knowingly submitted, and contractual or network consequences from payers who learn of the lapse. None of these outcomes are automatic once an exclusion is found, but the response window matters enormously.
Move through this checklist immediately:
- Remove the individual from any duties connected to federally reimbursable work, effective the moment the exclusion is confirmed.
- Quantify the affected claims, meaning every claim submitted for services that individual furnished, ordered, or prescribed during the exclusion period.
- Refund or adjust affected claims with the relevant payer rather than waiting for a demand.
- Consider OIG’s Self-Disclosure Protocol (SDP), which can meaningfully reduce penalty exposure compared to waiting for OIG to find the issue independently.
- Consult counsel before making public statements or formal disclosures, since the legal strategy around self-disclosure timing matters.
Keeping the documentation trail described earlier is what makes mitigation possible in the first place. If you can show a functioning monthly screening program with logged searches and verification steps, you have a materially stronger position when negotiating penalty reduction than an organization with no evidence of any screening effort at all.
Mandatory vs. Permissive Exclusions: What Is the Difference?
Not every exclusion carries the same weight, and understanding the distinction helps you interpret what a listing actually means for your risk exposure.
Mandatory exclusions are required by statute and apply to convictions for offenses like Medicare or Medicaid fraud, patient abuse or neglect, and felony convictions related to controlled substances. OIG has no discretion here. A mandatory exclusion carries a minimum exclusion period, commonly five years, though it can run longer depending on the severity and history of the offense.
Permissive exclusions give OIG discretion to exclude based on a broader range of conduct, including license revocation, suspension from a state health care program, submission of false or fraudulent claims, or fraud in a non-health-care government program. The exclusion period for permissive cases varies based on the specific circumstances and is not fixed by statute in the same way mandatory exclusions are.
For your screening program, the practical difference is smaller than it might seem. A listing is a listing, whether mandatory or permissive, and both carry the identical payment prohibition once entered on the LEIE. What the distinction actually helps with is context: understanding why someone was excluded can inform your broader risk assessment of that individual and whether related conduct might affect other parts of your background screening, even outside the exclusion question itself.
The Legal Framework Behind OIG Exclusion Authority
OIG’s exclusion authority traces to sections 1128 and 1156 of the Social Security Act, which together give the agency the power to exclude individuals and entities from participation in Federal health care programs and to bar payment for their services. This is not a discretionary internal policy. It is a statutory mechanism with real enforcement teeth behind it.
Exclusions do not happen instantly or without process. Most exclusion actions follow formal administrative proceedings, typically beginning with a Notice of Intent to Exclude, followed by an opportunity for the affected individual to appeal before an administrative law judge, and in some cases further review in federal court. That process matters for compliance officers because it means a listing on the LEIE reflects a documented, adjudicated determination rather than an allegation.
The Special Advisory Bulletin issued by OIG remains the most direct guidance document tying this statutory framework to practical screening expectations for providers, and it is the source most compliance programs cite when justifying their screening cadence to auditors or leadership. Beyond OIG’s own guidance, providers operating under Medicare Conditions of Participation and state Medicaid provider agreements often have parallel contractual obligations layered on top of the federal statute, which is why legal counsel should review your screening policy against both federal exclusion law and your specific program agreements.
What Compliance Failures Actually Look Like
The most common OIG exclusion screening failures share a pattern: the organization had a policy on paper but no consistent execution behind it.
A frequent scenario involves an agency that screens diligently at hire but never rechecks afterward. An employee clean at onboarding gets excluded eighteen months later following an unrelated licensing action, and the organization only discovers it during a payer audit, long after months of claims have already been submitted for that person’s services. The fix would have cost nothing more than a scheduled monthly batch run.
Another recurring failure involves contractors. An agency assumes its staffing partner is screening its own placements, never asks for proof, and later discovers the staffing agency’s screening process was informal or nonexistent. The agency bears the exposure anyway, because payment prohibition attaches to the service, not to who signs the paycheck.
A third pattern involves relying solely on the downloadable LEIE file without secondary verification. A common name generates a preliminary match, the compliance team assumes it is a false positive without confirming via SSN, and either wrongly clears an actually-excluded person or wrongly flags an innocent employee, creating a different kind of liability.
The organizations that avoid these outcomes share the same traits: a written policy defining scope and cadence, automated monthly checks rather than manual ones, mandatory secondary verification for every match, contractual flow-downs to vendors, and someone in leadership who actually reviews the KPIs rather than assuming the process runs itself.
How OMNI Intel Operationalizes Exclusion Screening
Everything described above, from identifier capture through monthly automation, secondary verification, audit logging, and vendor flow-downs, is a workflow problem before it is a compliance problem. OMNI Intel was built around that reality for public safety agencies, fire and EMS departments, dispatch centers, and the municipalities and nonprofits that support them.
The platform maps directly onto the screening lifecycle described in this article: identifier capture during pre-employment screening intake, scheduled monthly rechecks instead of manual reruns, secondary verification workflows before any match is acted on, and centralized audit logs that hold up under review. For agencies already using OMNI Intel for background investigations, exclusion screening plugs into the same case record rather than living in a separate spreadsheet nobody remembers to update.
Agencies piloting a defensible screening program should confirm the following before rollout:
- Every covered role, employees, contractors, volunteers, and board members, is mapped into the screening scope.
- Monthly automated checks are scheduled, not dependent on someone remembering to run them.
- A named reviewer owns match resolution with a defined turnaround time.
- Vendor and staffing agency attestations are collected and stored alongside internal screening logs.
One caution worth flagging for any agency structuring vendor relationships around screening: OIG’s own advisory opinion precedent warns that funding arrangements between vendors that could steer referrals can raise anti-kickback concerns, so keep screening vendor selection separate from any referral-based compensation structure.
| Point | Details |
|---|---|
| Screen at hire and monthly | Onboarding checks alone leave a gap; monthly rechecks match the LEIE’s own update cycle. |
| Verify before acting | Confirm any name match with SSN, EIN, or NPI through the LEIE Online Search before termination or removal. |
| Document everything | Keep search exports, verification logs, and match-resolution notes as your audit trail. |
| Flow requirements to vendors | Require attestations, audit rights, and indemnification clauses in every staffing and contractor agreement. |
| OMNI Intel supports the workflow | Automates monthly checks, secondary verification, and audit logging for public safety agencies through its pre-employment screening platform. |
A practitioner’s take on ownership and metrics
A written policy means nothing without someone checking whether it ran. I’d rather see an agency track three numbers monthly: percent of workforce actually covered by the last screening cycle, average time to resolve a potential match, and whether the monthly run happened on schedule at all. None of that belongs solely to HR. Compliance, HR, and revenue cycle should all see these numbers, and so should the board, because an exclusion discovered late is a leadership failure, not just an operational one.
— Matt
OMNI Intel Gives Your Agency an Auditable Screening Program
Running OIG exclusion screening manually across dozens or hundreds of employees, contractors, and volunteers is where most compliance programs quietly break down, not because anyone is negligent, but because spreadsheets do not scale and monthly recurring tasks get deprioritized the moment a hiring surge hits. OMNI Intel is built specifically for public safety agencies that need this handled reliably every single month, not just at the point of hire.
The platform folds exclusion screening into the same workflow as your broader pre-employment screening process, so identifier capture, verification, and documentation happen in one system instead of three. For agencies that also need ongoing background investigations or continuous employee monitoring after hire, the audit trail carries forward automatically rather than living in disconnected files that someone has to reconcile before an audit.
If your agency is still running LEIE checks by hand or trusting vendor attestations without verification, start by requesting a walkthrough of how OMNI Intel structures monthly screening and audit logging for public safety teams, and see where the gaps are in your current process before your next compliance review.
This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.
FAQ
What is OIG exclusion screening?
It is the practice of checking OIG’s List of Excluded Individuals and Entities (LEIE) to confirm that employees, contractors, or vendors are not barred from participating in Federal health care programs, which would prohibit payment for their services.
How often should you check the OIG exclusion list?
OIG recommends screening at onboarding and then monthly thereafter, since the LEIE itself updates every month and less frequent checks create documented gaps in due diligence.
What are mandatory exclusions under OIG rules?
Mandatory exclusions apply to convictions for offenses including Medicare or Medicaid fraud, patient abuse or neglect, and felony controlled substance convictions, and OIG has no discretion to avoid excluding these individuals.
How does someone get removed from the OIG exclusion list?
Reinstatement is not automatic once the exclusion period ends. The individual must apply for reinstatement, and OIG evaluates the request based on the background information governing exclusion authorities before restoring eligibility.
Should you use LEIE or SAM.gov for exclusion screening?
Use the LEIE as your primary source, since OIG states it provides more detailed information about health care exclusions than SAM.gov, which covers a broader but less detailed range of federal exclusions.




