Read the claims. Separate real red flags from the noise. Choose the right action, whether that's monitoring, educating the provider, opening an investigation or referring the case out. Then mine the data for the next lead and put a defensible dollar figure on the overpayment.
The action is based on two things: how much harm there is if the pattern is real (severity), and how likely it is to be fraud rather than error (likelihood). An investigator who refers everything wastes law enforcement's time. One who only educates lets fraud keep getting paid.
Each case has real red flags mixed with decoys, which are facts that look reassuring or suspicious but don't change the answer. Pick the flags you would build the case on, choose the action, then submit to see the debrief and the next records to pull.
Most strong leads don't come from tips. They come from comparing each provider to peers in the same specialty and area. Pick a metric below. The table ranks providers by z-score, which measures how far each one sits from the peer average. Above 2 is worth a look, and above 3 is worth a case.
Peer group: family medicine, one metro area, 12 months of paid claims.
This works the same way as the HHS-OIG RAT-STATS workflow. Draw a random sample from the provider's paid claims and audit each sampled claim. Then project the sample's overpayment onto every claim. The standard demand is the lower limit of the 90% two-sided confidence interval, which is deliberately conservative and favors the provider.
Provider: fictional DME supplier. Universe: 12 months of paid claims.
This is the working set a health plan SIU investigator uses day to day, grouped by the job it does in a case: find the lead, confirm the facts, measure the loss and document the referral.
Precision is how many of your flags were real. Recall is how many real flags you caught. Tier accuracy is whether you chose the right action. A strong investigator scores high on all three without over-referring.