June 24, 2025
WHAT YOU NEED TO KNOW: CMS is warning providers about fraudulent faxed requests for medical records falsely claiming to be part of Medicare audits. CMS does not initiate audits via fax.
The Centers for Medicare & Medicaid Services (CMS) is warning Medicare providers about a rise in phishing scams involving fraudulent fax requests for medical records. These schemes involve bad actors impersonating CMS and falsely claiming the requests are related to a Medicare audit.
Unlike traditional email phishing, these scams use fax machines to appear more legitimate and catch practices off guard. CMS clarified that it does not initiate medical record audits via fax and urged physicians to remain vigilant.
Phishing is a form of social engineering that attempts to deceive recipients into disclosing sensitive information. While email attacks remain common, fax-based scams are a growing threat, especially when they mimic official-looking audit requests.
What to do:
- Do not respond to any suspicious fax requests for records.
- Verify the legitimacy of any audit or documentation request through Noridian.
- Report suspected fraud or phishing attempts to CMS.
For more information and guidance, visit cms.gov/fraud.