AI use case

AI for healthcare claims fraud, waste and abuse detection

AI that reads healthcare claims and provider billing patterns to flag fraud, waste and abuse before or shortly after a claim is paid, sending every flag with its reasons to a payment integrity investigator, while a narrow set of clear rule violations can be denied automatically before payment.

By Len Debets · Last verified 29 September 2026 · 2 public deployments

At least USD 20.4 million
Cost savings
Centers for Medicare and Medicaid Services (organization claim).
USD 6 million to USD 180 million
Indicative value per year
A health plan paying 10 million medical claims a year. Worked example, see how it is calculated.

What problem does it solve?

Health insurers and public payers handle enormous claim volumes: the US Government Accountability Office reported that in fiscal year 2016 alone, Medicare covered about 57 million elderly and disabled beneficiaries at a cost of about 699 billion US dollars. A share of paid claims are not what they claim to be: services billed but never given, codes inflated to a more expensive procedure, tests ordered mainly to generate a claim. The National Health Care Anti Fraud Association's conservative estimate is that losses to health care fraud alone run 3% of total US health care expenditure, with some government and law enforcement agencies placing the loss as high as 10%. Waste and abuse add further losses that this estimate does not size separately.

Traditional controls catch some of this with static rules and after the fact audits, but rules do not adapt as billing schemes change, and manual review cannot keep pace with claim volume. The result is either large sums paid out that are never fully recovered, or slow, blunt reviews that delay payment to honest providers along with the dishonest ones.

The work splits into two very different jobs: a small set of clear, documented rule violations that can be denied automatically before a claim pays, and a much larger set of suspicious patterns that need a trained investigator, clinical judgement and, eventually, a decision to suspend a provider or refer the case to law enforcement.

  • The National Health Care Anti Fraud Association estimates that financial losses to health care fraud run into the tens of billions of dollars a year; a conservative estimate is 3% of total health care expenditure, while some government and law enforcement agencies place the loss as high as 10%, which could mean more than 300 billion US dollars.The Challenge of Health Care Fraud (2019)

How does it work?

  1. Screen every claim before it pays, not just after. A first layer of deterministic edits checks each claim against documented billing and coverage rules and denies the ones that clearly break them, the way CMS's Fraud Prevention System denies claims that misstate where a service was provided.
  2. Score the rest for suspicious patterns. A predictive model looks at billing patterns across a provider's claims over time, such as more services than could reasonably fit in a day, unusual coding mixes, or billing that jumps after a policy change, and ranks providers and claims by how much they resemble confirmed fraud, waste or abuse.
  3. Build the case, not just the score. Each flag comes with the specific pattern that triggered it and the provider's recent billing history, so an investigator opens a case file rather than a bare number.
  4. Investigate and decide. A special investigations unit or program integrity team reviews the flagged claims and providers, requests medical records where needed, and decides whether to recover money, suspend payments or refer the case to law enforcement.
  5. Share signals across payers. Organized schemes often bill several payers at once, so participating in a cross payer data sharing effort, such as the Healthcare Fraud Prevention Partnership that CMS helped establish, surfaces patterns no single payer's own data would show.
Audience
Back office
Autonomy
Assist
Adoption
Early adopters
Channels
API and system to system, Internal tools

What is it worth?

Benchmarks are computed from the public deployments below: one data point per organization per KPI, with who made each claim.

Value benchmarks for AI for healthcare claims fraud, waste and abuse detection
KPIMedianReported rangeData pointsClaimed by
Cost savingsNot pooled
at least USD 20.4 million
11 organization

Value drivers: Risk and loss reduction, Lower cost to serve, Compliance quality.

Indicative value

A health plan paying 10 million medical claims a year

USD 6 million to USD 180 million

Fraudulent payments avoided per year per year

How this is calculated

Formula: claimsPerYear * fraudShare * avgClaimValue * preventionRate. The low scenario uses every low input, the high scenario every high input.

InputLowHighBasis
Paid medical claims per year claimsPerYear, claims per year10,000,00010,000,000The reference health plan.
Share of paid claim value lost to health care fraud fraudShare, fraction of paid claim value0.030.1NHCAA's conservative estimate is that losses to health care fraud run 3% of total health care expenditure; some government and law enforcement agencies place the loss as high as 10%. This sizes fraud only; it does not include waste or abuse. Source
Average paid amount per medical claim avgClaimValue, USD per claim4001,200Editorial assumption for a mixed medical claims book, replace with your own average paid amount per claim.
Share of fraud value the model and investigations team stop before payment preventionRate, fraction of fraud value stopped before payment0.050.15Editorial assumption, replace with your own. For scale, CMS reported that its Fraud Prevention System's rule based prepayment edits, which do not score claims for risk, denied nearly 324,000 claims and saved more than 20.4 million US dollars in fiscal year 2016 alone, as reported by the Government Accountability Office; that figure is a small fraction of NHCAA's fraud estimate for the whole US health system, so this range is not benchmarked against it. Source

What it leaves out: Gross avoided payments only, and only for the fraud share NHCAA sizes; it leaves out waste and abuse, which are not sized separately here, the cost of running the model and the investigations team, false positives that delay legitimate provider payments, and fraud caught only after payment through postpay recovery.

Who already uses it?

2 public deployments, strongest evidence first. Grades: A regulator or audit, B the organization itself, C vendor case study, D anonymous or estimate.

Highmark Inc.

United States · Healthcare · 2020

ProductionGrade B

Highmark Inc.'s Financial Investigations and Provider Review (FIPR) department announced in February 2020 that it had begun using artificial intelligence to identify potentially fraudulent activity earlier than its existing rules based tools, through a partnership with Codoxo's FraudScope platform that Codoxo's own press release says started in 2019. Highmark's Vice President of Financial Investigations and Provider Review, Kurt Spear, said Highmark's Payment Integrity program runs 28 initiatives to help ensure claims payment accuracy, 15 of them embedded within FIPR, and described AI as helping the team predict aberrancies earlier and adapt more quickly to changing provider behaviour than traditional tools. Highmark's own announcement reports FIPR's total financial impact for 2019, 260 million US dollars, without attributing any part of it to AI, since the tool had only "just recently" gone live; Codoxo's press release, unlike Highmark's, attributes the 2019 escalation in that total "in part" to the newly implemented AI, alongside the department's existing manual and rules based work, without isolating an AI specific savings figure.

No outcome disclosed.

Centers for Medicare and Medicaid Services

United States · Government and public sector · 2011

ScaledGrade B

The Centers for Medicare and Medicaid Services (CMS) built the Fraud Prevention System (FPS), a data analytic system implemented in 2011 that develops leads for fraud investigations by CMS program integrity contractors and denies improper Medicare fee for service claims before payment through automated, rule based prepayment edits. The US Government Accountability Office (GAO) reviewed CMS's use of FPS and reported that, in fiscal year 2016, FPS backed about a fifth of Medicare fraud investigations, contributed to provider payment suspensions during ongoing investigations, and its prepayment edits denied claims that violate documented Medicare rules or policies. GAO states that these edits "do not analyze individual claims to automatically deny them based on risk alone or the likelihood that they are fraudulent," and that CMS does not have the authority to use FPS to deny a claim automatically based on risk alone. CMS also helped establish the Healthcare Fraud Prevention Partnership, which pools claims data across public and private payers to spot billing patterns no single payer's data would show.

  • Cost savings: at least USD 20.4 million, fiscal year 2016
    "CMS reported that FPS edits denied nearly 324,000 claims and saved more than $20.4 million in fiscal year 2016."
    Claimed by: organization
  • Cost savings: about USD 6.7 million, fiscal year 2016
    "In fiscal year 2016, CMS reported that 90 providers had their payments suspended because of investigations initiated or supported by FPS, which resulted in an estimated $6.7 million in savings."
    Claimed by: organization

How do you implement it?

A model agnostic playbook: what to prepare, the order to build in, and what goes wrong.

Data you need

  • Historical paid and denied claims labelled by a confirmed fraud, waste or abuse outcome
  • Provider enrollment, network and billing history data
  • Current procedural and diagnosis coding rules and the payer's own billing policies

Systems to integrate

  • Claims adjudication and payment system, for prepayment edits
  • Provider data management and network systems
  • Case management system for the special investigations unit
  • Legal and law enforcement referral workflow, for confirmed fraud cases

Complexity: High

Detecting fraud, waste and abuse needs claims, provider, eligibility and often medical record data joined at the claim line level, current procedural and diagnosis coding knowledge, and a defensible audit trail, because every flag can end in a provider investigation, a payment suspension or a law enforcement referral.

  1. 1

    Start with clear, defensible rules before the model

    Encode known billing violations, such as a place of service mismatch, as deterministic prepayment edits, the way CMS's Fraud Prevention System does, before adding predictive scoring on top.

  2. 2

    Separate the prepay stop from the postpay lead

    Decide which flags block payment automatically under strict, documented criteria, and which only generate a lead for a human investigator. Most flags should be the latter.

  3. 3

    Ground the model in confirmed outcomes

    Train and validate on claims with a documented investigation outcome, not just claims that "look unusual," and revalidate regularly as coding and billing patterns shift.

  4. 4

    Build the investigator workflow, not just the score

    Give investigators the claim, the provider's billing history and the specific reason for the flag, so they are not starting from a blank claim.

  5. 5

    Coordinate with peers and law enforcement

    Contribute to and use a cross payer data sharing programme; organized fraud usually spreads across payers, and no single payer's data shows the whole pattern.

Guardrails

  • No predictive fraud score ever triggers an automatic denial on its own; the system denies a claim automatically only through a deterministic rule edit, and every predictive score, however high, goes to a human investigator as a lead, not a denial
  • A provider is never suspended or reported to law enforcement without human sign off and a documented investigation
  • Regular review of false positive rates by specialty, to catch a model that disproportionately flags one type of provider or patient population
  • Legal review before any bulk payment suspension or law enforcement referral

KPIs to instrument

  • Confirmed fraud, waste or abuse found per investigator hour, against the manual baseline
  • False positive rate on flagged claims, by specialty and payer
  • Value of prepayment edits and postpay recoveries, tracked separately
  • Time from claim submission to a confirmed investigation outcome

Human in the loop

Investigators, clinical reviewers and compliance staff make every provider suspension, recoupment and law enforcement referral decision. The model's job is to surface the claims and providers worth their time faster than manual sampling or a static rule set could.

Common failure modes

Automatic edits that block legitimate care
A prepayment edit written too broadly denies claims for care that was actually delivered and coded correctly, delaying provider payment. Test every edit thoroughly against real claims before it goes live; CMS has its Medicare Administrative Contractors help develop and test FPS edits before they go into the system, to make sure they work as intended.
Model drift as billing patterns shift
Fraud schemes adapt once providers learn what gets flagged. Retrain on recent confirmed outcomes and watch for a falling hit rate, often the first sign a scheme has moved on.
Savings claimed that the model did not cause
A payment integrity programme's total savings can get attributed to a new AI tool that only touched a fraction of it. Track the model's own attributable savings separately from the rest of the programme.

What are the risks and rules?

EU AI Act

Depends on design

Claims fraud, waste and abuse detection is not itself listed in Annex III. Annex III point 5(a) only covers AI used by or on behalf of public authorities to evaluate a natural person's eligibility for essential public assistance benefits and services, or to grant, reduce or revoke them, which can cover statutory health schemes run by or for public bodies such as Medicare; it does not cover a private health insurer denying a member's own claim. For a private insurer, only Annex III point 5(c), risk assessment and pricing in life and health insurance, can make a system high risk, and claims fraud, waste and abuse detection by itself is not covered by it. Provider level detection that never decides a patient's own entitlement to care stays outside Annex III either way.

Guidance

Controls to put in place

  • Documented investigation and sign off before any provider payment suspension or law enforcement referral
  • False positive and disparate impact monitoring by provider specialty and patient population
  • Independent validation of every automated prepayment edit before and after launch
  • Data sharing governance for any cross payer fraud data pooling

Frequently asked questions

How is this different from general insurance claims fraud detection?
General insurance claims fraud detection looks for staged accidents, inflated losses and organized rings in property, casualty and life claims. Healthcare payer fraud, waste and abuse detection is built around medical coding and billing rules, such as upcoding, unbundling and services never rendered, checked against payment policy rather than a police report.
What share of healthcare spending is lost to fraud, waste and abuse?
The National Health Care Anti Fraud Association's conservative estimate is that losses to health care fraud alone run 3% of total health care expenditure, with some government and law enforcement agencies placing the loss as high as 10%. That figure covers fraud specifically; NHCAA does not size waste and abuse separately, and neither figure is specific to any one payer's book, so use it only as an order of magnitude.
Does the AI ever deny a claim on its own?
In CMS's Fraud Prevention System, automatic denials come only from deterministic prepayment edits that check a claim against a documented Medicare rule, such as an impossible place of service. The Government Accountability Office reports that, according to CMS officials, CMS "does not have the authority to use FPS to automatically deny individual claims based on risk" and that FPS edits "do not analyze individual claims to automatically deny payments based on risk alone or the likelihood that they are fraudulent." A predictive fraud score only produces a lead for a human investigator; it never denies a claim on its own.
Is this the same tool that reviews prior authorization requests?
No. Prior authorization and claims adjudication support checks a specific request or claim against clinical and policy criteria for a clinician or adjudicator to decide. Fraud, waste and abuse detection looks across claims and providers over time for patterns that indicate deliberate wrongdoing, not a single coverage decision.

How to cite this page

Blits.ai AI Use Case Library, "AI for healthcare claims fraud, waste and abuse detection", last verified 29 September 2026, https://www.blits.ai/ai-use-cases/healthcare-claims-fraud-waste-abuse-detection. Licensed under CC BY 4.0. Method: how we verify use cases.

Changelog
  • 29 September 2026: First published

Related use cases

Insurance

AI for insurance claims fraud detection

AI that scores every insurance claim for fraud from first notice of loss onwards, combining claim, policy, document, image and network data to find suspicious claims, organised rings and inflated losses, and sends each alert with its reasons to a claims handler or special investigations unit for review.

Deployments
5 public, best grade B
Autonomy
Assist
InsuranceHealthcare

AI for health insurance prior authorization and claims adjudication support

AI that reads prior authorization requests, medical claims and appeals with their clinical and billing documents, extracts diagnoses, treatments and costs, checks them against the policy and published clinical criteria, and prepares a summary and recommendation for a clinician or adjudicator, who makes every adverse decision.

Deployments
5 public, best grade B
Reported handling time reduction
about 50%
Acentra Health, vendor claim
Healthcare

AI medical coding for clinical encounters

AI that reads the clinical documentation of an encounter and assigns the diagnosis and procedure codes (such as ICD-10, CPT and HCPCS) needed for billing and reporting, either as suggestions for a certified coder or autonomously for encounters it can code with high confidence, sending the rest to coders with the reasons.

Deployments
3 public, best grade B
Reported accuracy
98.3%
Your Health, organization claim
BankingPayments and cards

AI for application and identity fraud detection

AI that checks incoming account and loan applications for forged or AI generated documents, synthetic and stolen identities, and coordinated application rings, by analysing documents, device and application data across the whole queue and cross checking against bureau and official sources.

Deployments
6 public, best grade B
Reported detection improvement
2.5x
Department for Work and Pensions, organization claim