$1.42 Billion Medicare DME Fraud Case Exposes Weak Points in Supplier Enrollment and Billing
WASHINGTON—August 24, 2026—A federal investigation into a transnational healthcare fraud organization has exposed how criminals can combine fraudulent medical equipment suppliers, fake medical orders and stolen Medicare beneficiary information to push massive volumes of false claims through the U.S. healthcare system.
Between July 2022 and July 2024, the organization allegedly used Florida-based Royce Medical Supply LLC to submit at least $1.42 billion in false and fraudulent claims to Medicare, Medigap supplemental insurers and other health insurance programs for continuous glucose monitors, urinary catheters and other durable medical equipment that was not actually dispensed. Federal prosecutors said CMS suspended reimbursement on nearly all of those claims, although some payments were made.
The case has become a central example in a new HHS Office of Inspector General review of Medicare’s durable medical equipment system. OIG says fraudsters repeatedly exploit three basic components of the program: a Medicare-enrolled supplier, a physician order and a beneficiary’s identification number. Medicare’s DMEPOS market alone accounts for more than $7 billion a year in Original Medicare payments, making it a significant target for organized fraud.
The investigation also shows that the problem extends beyond one company or one set of claims. Operation Gold Rush, the broader federal investigation, has resulted in 35 people being charged and 16 convictions so far, according to the Justice Department. An Ohio defendant recently pleaded guilty to laundering about $3.4 million in proceeds connected to the organization.
The fraud was built around a legitimate Medicare billing structure
The significance of the case is not simply the amount of money involved. Investigators say the organization exploited components that are normally designed to make Medicare claims legitimate.
A DME supplier needs Medicare billing privileges. Medical equipment generally requires an appropriate provider order. And claims must contain information identifying the beneficiary.
According to HHS-OIG, criminals have learned to manipulate each of those elements.
Fraudsters can establish or acquire Medicare-enrolled DME companies, use straw or nominee owners to hide the people actually controlling the businesses, obtain fraudulent physician orders and use stolen or improperly obtained Medicare beneficiary identifiers to generate claims.
Once those pieces are connected, a claim can look legitimate within the billing system even when the equipment was never needed or delivered.
That is why OIG’s new white paper does not focus only on individual fraudulent claims. It examines the system vulnerabilities that allow fraudulent suppliers and false documentation to enter the claims process in the first place.
The $1.42 billion was billed — not necessarily paid
The distinction is important.
The Justice Department says the organization submitted at least $1.42 billion in false claims through Royce Medical Supply during the two-year period. That number represents claims submitted for reimbursement, not an equivalent loss to Medicare.
CMS suspended reimbursement on nearly all of those claims, according to federal prosecutors. Some claims were paid, however, and investigators traced a portion of the proceeds into the organization’s money-laundering network.
That payment distinction is one reason the case is also important as an example of how early fraud detection can limit financial losses.
Instead of waiting for every questionable claim to be paid and attempting to recover the money later, CMS can suspend payments when its systems detect suspicious activity.
$3.4 million in proceeds were moved through Ohio accounts
The financial trail led investigators to Eldar Zarbavel, 45, of Pepper Pike, Ohio.
According to the Justice Department, Zarbavel opened bank accounts in Northeast Ohio for Royce Medical Supply and helped move money generated by fraudulent healthcare claims.
Between June and July 2024, prosecutors said he facilitated the deposit, transfer and withdrawal of approximately $3.4 million in fraud proceeds.
The money was then moved through additional accounts and entities as part of the organization’s effort to disguise the source of the funds. Zarbavel pleaded guilty to one count of money laundering and faces a maximum sentence of 20 years in federal prison.
His case is one piece of a much larger investigation.
Operation Gold Rush shows the broader scale
The Royce Medical Supply claims are part of the larger Operation Gold Rush investigation, which federal prosecutors describe as the largest healthcare fraud case ever prosecuted by the Justice Department.
So far, 35 individuals have been charged and 16 have been convicted in connection with the organization, according to DOJ. The organization is described as a foreign-based criminal network operating from Russia and elsewhere and targeting both Medicare and private health insurers.
The broader investigation has uncovered other massive DME-related schemes, including one involving urinary catheters.
In a separate case examined by GAO, 15 providers allegedly billed Medicare for more than $4 billion in urinary catheters that were never supplied. CMS used data analytics to identify the unusual billing and suspended payments before most of the money could leave the program.
That case demonstrates why the federal government increasingly relies on claims data and unusual billing patterns rather than waiting for traditional complaints or audits.
CMS says it prevented billions in potentially fraudulent payments
A March 2026 Government Accountability Office review provides a broader look at how Medicare is responding.
GAO found that CMS estimated it prevented approximately $11.9 billion in potentially fraudulent payments during fiscal years 2022 through 2024.
The total included approximately:
| CMS action | Potentially fraudulent payments prevented |
|---|---|
| Payment suspensions | $2.579 billion |
| Provider revocations and deactivations | $7.962 billion |
| Automated prepayment denials | $132 million |
| Overpayment recoveries | $652 million |
| Prepayment claims reviews | $27 million |
| Law-enforcement referrals | $554 million |
| Total | $11.906 billion |
GAO cautioned that some figures, including payment suspensions, are based on estimated cost avoidance rather than money that would otherwise certainly have been paid.
The numbers nonetheless show how much of the federal response now happens before payment.
Medicare beneficiary IDs have become another target
The supplier is only one part of the vulnerability.
GAO found that Medicare fraud schemes frequently depend on stolen or improperly obtained Medicare beneficiary identifiers, or MBIs.
Those identifiers are required elements of Medicare claims, making them valuable to criminals. GAO said fraudsters can obtain beneficiary information through data breaches, cold calls, deceptive marketing, compromised lookup tools or other methods.
In one test, GAO investigators purchased Medicare beneficiary information from online marketplaces while posing as fraudsters. In two separate purchases, they obtained beneficiary personal information, including Medicare identifiers; one purchase included images of beneficiary identification cards. The information was referred to law enforcement.
That finding adds another dimension to the DME fraud problem: a criminal organization does not necessarily need to invent a beneficiary. It can use the identity of a real Medicare enrollee to make a fraudulent transaction appear authentic.
Fake physician orders can complete the transaction
Medical orders provide another potential weak point.
For DME to qualify for Medicare coverage, the equipment generally must be medically necessary and ordered by an appropriate provider.
GAO found that fraudsters may obtain provider orders by using the identity of an uninvolved physician, working with a complicit practitioner or purchasing fraudulent orders.
In one DOJ case cited by GAO, a Texas doctor signed thousands of medical records and orders for orthotic braces and genetic tests that falsely represented the services as medically necessary. The doctor was sentenced in 2025 to 10 years in prison and ordered to pay $26 million in restitution.
That example helps explain why OIG is recommending stronger verification around physician orders rather than relying solely on the existence of an order in a claim file.
CMS has already taken an unusual step on DME suppliers
The federal response has moved beyond investigations.
On February 27, 2026, CMS imposed a temporary nationwide six-month moratorium on new Medicare enrollment for certain DMEPOS medical supply companies.
The restriction covers initial applications for specified supplier categories and certain changes in majority ownership. CMS said the action was intended as a program-integrity measure in an area with significant fraud, waste and abuse concerns.
CMS announced the moratorium after saying it had stopped more than $1.5 billion in suspected fraudulent DMEPOS billing during the previous year.
The move is significant because supplier enrollment is the entry point into Medicare’s billing infrastructure. If fraudulent operators cannot obtain or manipulate billing privileges, one major part of the fraud chain becomes harder to establish.
OIG wants the system to stop fraud earlier
HHS-OIG’s August 2026 white paper argues that more targeted action is needed even as CMS expands its fraud-fighting capabilities.
CMS has created a Fraud Defense Operations Center to more proactively identify suspicious billing and suspend payments. But OIG says the continuing evolution of DME fraud requires stronger attention to the underlying vulnerabilities.
The watchdog’s framework centers on three questions:
Is the supplier legitimate?
Is the medical order genuine and medically necessary?
Does the beneficiary information belong to a real person whose equipment was actually ordered and received?
Closing gaps at those points could make it substantially harder for organized fraud networks to manufacture claims at scale.
The problem is larger than one fraud network
The DME cases are part of a wider federal effort against healthcare fraud.
GAO has designated Medicare as a high-risk program, in part because of its complexity and exposure to fraud. The agency found that common schemes can involve billing privileges, beneficiary identifiers, provider orders and targeted services working together.
GAO also found that organized criminal groups, including groups operating from outside the United States, are increasingly targeting Medicare. Investigators reported that some foreign networks use U.S.-based nominal owners to obtain provider billing privileges and then route proceeds abroad.
The report also warned that fraudsters are adopting new techniques, including artificial intelligence, to potentially generate fraudulent claims and fabricated medical records at greater scale. Another emerging pattern is the so-called “bust-out” scheme, in which providers suddenly submit extremely large volumes of claims before investigators can intervene.
What the case means for Medicare beneficiaries
For beneficiaries, DME fraud is not simply a problem of government spending.
Fraudulent claims can involve equipment a person never requested, never needed or never received. The misuse of beneficiary identifiers can also expose sensitive personal information and create claims records that do not reflect the person’s actual care.
The scale of the federal response shows why the government is increasingly trying to detect these patterns before payment.
The objective is not only to recover money after fraud occurs, but to prevent fraudulent suppliers from entering Medicare, stop suspicious claims while they are being processed and protect beneficiary information that criminals can use to manufacture additional claims.
What happens next
The new OIG report puts pressure on CMS to strengthen all three points in the billing chain: supplier enrollment, physician orders and beneficiary identification.
CMS has already responded with stronger enrollment screening, payment suspensions, data analytics and the nationwide DMEPOS enrollment moratorium. GAO’s findings show that those tools can prevent billions of dollars in potentially fraudulent payments, but the continuing emergence of large DME schemes suggests that fraudsters are adapting as quickly as safeguards improve.
The Royce Medical Supply case therefore represents more than a large false-claims number. It illustrates how a sophisticated criminal network can combine legitimate Medicare infrastructure with false identities, questionable documentation and financial laundering to create claims at enormous scale — and why federal agencies are now focusing increasingly on stopping the fraud before the payment is made.
The Bottom Line
A federal investigation tied to Operation Gold Rush shows how organized criminals allegedly exploited Medicare’s DME billing infrastructure through fraudulent suppliers, fake documentation and beneficiary information. The government stopped most of the claims in the Royce Medical Supply case before reimbursement, while the broader investigation has produced 35 charges and 16 convictions. HHS-OIG’s latest review now puts the focus on closing the three entry points criminals repeatedly exploit: supplier enrollment, medical orders and beneficiary IDs.