The New York Attorney General’s Office has secured $6 million from three Western New York nursing homes for a fraudulent billing scheme that saw the homes submit thousands of fake Medicaid claims over a period of four years, AG Letitia James said Monday.
According to the AG’s office, Safire Rehabilitation of Northtowns, Safire Rehabilitation of Southtowns and Williamsville Suburban Nursing Home (the Safire homes) submitted false data that increased their Medicaid reimbursement rates from July 1, 2016 through Dec. 31, 2020.
“Nursing homes that commit financial fraud are stealing funds meant to provide care for our most vulnerable,” James said in a statement. “The Safire homes used fraudulent data to rake in millions of dollars from Medicaid without regard for the needs of the residents they were supposed to be serving. My office has rooted out fraud and resident neglect in nursing…
IT & DATA SECURITY (MITIGATING THE “INSIDER THREAT”)
As seen in the TD Bank case, an employee with too much “access” can sell your customer data to syndicates.
- Principle of Least Privilege (PoLP): Employees should only have access to the specific folders and databases required for their current task.
- Access Revocation: Have a “Termination Checklist” that ensures all digital access (Email, VPN, Banking) is revoked within 60 minutes of an employee resigning or being dismissed.
- System Logs & Audit Trails: Enable “Read/Write Logging” on your server. If a customer’s data is leaked, you need to know exactly which login accessed that record and at what time.
- Encryption at Rest: Ensure that sensitive files (like your customer ID numbers or payroll spreadsheets) are encrypted so that if a staff member copies them to a USB, they cannot be read.
