$703 Million Medicare Fraud: How the Scheme Worked & What Are Xecta Medical Billing Zero-Tolerance Standards
FOR IMMEDIATE RELEASE — One of the most significant Medicare fraud cases in recent history has resurfaced in public attention after U.S. federal authorities confirmed that four of five charged defendants in the $703 million scheme remain at large and may be located in Pakistan or the United Arab Emirates. The case — charged in June 2025 as part of the U.S. Department of Justice's 2025 National Health Care Fraud Takedown — involved a Pakistan-based call center, AI-generated fake patient consent recordings, stolen Medicare beneficiary data, and fraudulent DME billing through networks of straw-owned U.S. companies.
Xecta Technologies LLC, through its Xecta Medical Billing (XMB) division, issues this statement to inform its clients, prospective partners, and the broader healthcare provider community about the verified facts of this case — and to publicly restate the compliance standards, operating philosophy, and billing ethics that have governed every engagement XMB has conducted since its founding.
What Happened: The Verified Facts
Federal prosecutors in the Northern District of Illinois charged five Pakistani nationals in June 2025 in connection with a fraud scheme that generated fraudulent claims submitted to Medicare and Medicare Advantage plans between January 2023 and April 2025. The case was announced as part of the DOJ's 2025 National Health Care Fraud Takedown — the largest healthcare fraud enforcement action in U.S. history — charging 324 defendants across 50 federal districts in connection with more than $14.6 billion in alleged healthcare fraud.
The Numbers Behind the $703 Million Fraud
The Defendants
Five Pakistani citizens were charged in the Northern District of Illinois — all five also charged in an alleged money-laundering conspiracy. The indictment identifies:
- Ruknuddin "Rick" Charolia — alleged co-operator and owner of Hello International Marketing Solutions (HIMS), the Pakistan-based call center at the center of the scheme
- Aamir Ali Arif — alleged co-operator of HIMS
- Shearyar Arif — accused of distributing stolen Medicare beneficiary data
- Fizza Farid — alleged HIMS operative and nominee owner of a U.S.-based DME provider; believed to have fled for Pakistan in late April 2025 via Mexico and Turkey
- Faizan Saleem — accused of distributing Medicare beneficiary data and recruiting straw owners for U.S.-based DME entities
Four Defendants Remain at Large
As of September 2026, four of the five defendants — Fizza Farid, Faizan Saleem, Shearyar Arif, and Ruknuddin "Rick" Charolia — remain fugitives. The HHS Office of Inspector General has publicly identified all four and indicated they may be in Pakistan or the UAE. Federal pursuit is ongoing.
Case at a Glance
| Fact | Detail |
|---|---|
| Scheme Duration | January 2023 – April 2025 |
| Charges Filed | June 2025 — Northern District of Illinois |
| Broader Takedown | 324 defendants, $14.6B in alleged fraud — largest in U.S. history |
| Products Fraudulently Billed | OTC COVID-19 test kits, durable medical equipment, genetic tests |
| Technology Used | AI-generated deepfake audio to fabricate patient consent |
| Charges Include | Healthcare fraud conspiracy, money laundering conspiracy |
| Defendants Status (Sept. 2026) | 4 of 5 remain fugitives — believed in Pakistan or UAE |
Sources: U.S. Department of Justice Office of Public Affairs; IRS Criminal Investigation Division; HHS Office of Inspector General; CMS Newsroom; Medical Economics; The Media Line. All facts reflect publicly available federal charging documents and official government announcements.
How the Scheme Operated
The scheme was transnational in design and deliberately engineered to obscure the criminal chain between data theft and fraudulent billing. Federal prosecutors described the following five-step operational sequence:
- Data theft and acquisition: HIMS operated a call center and obtained Medicare beneficiary identification numbers through hacking, scraping publicly accessible websites, and running deceptive sites that falsely advertised free healthcare products to lure seniors into providing their personal information.
- AI-fabricated consent: Defendants allegedly used artificial intelligence to manufacture audio recordings making it appear Medicare patients were personally requesting products they never sought. These fabricated recordings were submitted to Medicare as purported patient consent.
- Distribution of stolen data: Stolen Medicare beneficiary data — paired with AI-generated consent files — was sold or distributed to U.S.-based DME companies and laboratories controlled through nominee (straw) owners installed specifically to appear as legitimate operators.
- False claim submission: Those U.S.-based entities submitted claims for OTC COVID-19 tests, DME, and genetic tests that beneficiaries had never requested, never received, and in many cases had never been contacted about.
- Money laundering: Proceeds were transferred from U.S. accounts to personal accounts overseas. At least $45.1 million was documented as transferred for personal use by defendants.
AI Was Used to Fabricate Patient Consent — Not Assist It
The use of artificial intelligence to generate deepfake audio recordings that mimicked real Medicare patients consenting to DME products marks a significant escalation in how fraud is executed. Real patients had their voices and identities imitated without their knowledge. These fabrications were submitted as clinical evidence to Medicare. This is not a minor procedural violation — it is identity fraud combined with healthcare fraud, executed at industrial scale using technology that was designed to serve patients, not exploit them.
Why This Case Matters to Every Legitimate Billing Operation
The $703 million fraud did not happen because the Medicare system failed. It happened because a small group of individuals made deliberate, calculated decisions to steal patient data, manufacture false documentation, and exploit billing infrastructure — from overseas. The harm was not abstract. Real Medicare beneficiaries had their personal health information stolen and weaponized. Real taxpayer funds were diverted from the healthcare system. Real DME companies operating legitimately faced heightened scrutiny and audit pressure as a direct consequence of fraud committed in their sector.
Cases of this scale increase enforcement pressure, tighten payer scrutiny, and erode the trust that clean billing relationships are built on. Higher OIG audit rates, more aggressive MAC Additional Documentation Requests, and intensified pre-payment review are direct downstream consequences that fall on every legitimate billing operation — not just the fraudsters. This is why cases like this one are not abstract compliance news. They affect the day-to-day operating environment of every honest provider and billing company in the industry.
XMB Billing Standards vs. The Fraud — A Direct Comparison
The scheme described in the federal indictment violated every standard that governs legitimate medical billing. The comparison below is not marketing language — it is a factual account of how XMB's operations differ from each element of the fraud at a structural level.
| Fraud Element | What the Fraudsters Did | What XMB Does |
|---|---|---|
| Patient Consent | Used AI to fabricate audio recordings of patients consenting to products they never requested | Bills only for documented, physician-ordered services patients actually received. No claim submitted without a legitimate provider order supported by a real patient encounter. |
| Patient Data Handling | Obtained Medicare IDs through hacking, scraping, and deceptive sites — then sold that data | Accesses patient data exclusively through HIPAA-compliant channels established with contracted providers. Data is never sold, shared, or used beyond the specific billing purpose. |
| Claim Accuracy | Submitted $703M in claims for products never requested or received by beneficiaries | Every claim corresponds to a service actually rendered, documented in the clinical record, and coded per CMS and payer guidelines. Billing for services not rendered is grounds for immediate contract termination. |
| Business Structure | Installed nominee (straw) owners at U.S. entities to obscure who was operating them | Xecta Technologies LLC is a registered company operating transparently under its actual principals. XMB does not represent anonymous entities or obscure ownership structures. |
| Staff Credentials | No certified coders — marketing and data operations drove all billing decisions | Leadership holds active AAPC certifications: CPC, CPB, and CPMA. All coding decisions are made by or under direct supervision of credentialed specialists. |
| Kickbacks | Paid and received kickbacks throughout the referral and billing chain | Does not pay, receive, or participate in any kickback arrangement. Compensation is exclusively the agreed service fee paid directly by contracted provider clients. |
| Use of Technology | Used AI to generate fabricated consent evidence to deceive Medicare | Uses technology to improve accuracy and catch errors before submission. Technology supports compliance — it does not circumvent it. |
| Audit Readiness | Defendants fled the country when investigation began — four remain fugitives | Every claim is documented, traceable, and defensible. Proactively prepares clients for MAC ADR requests, OIG audits, and payer recoupment reviews. |
Statement from XMB Leadership
Cases like this one are a reminder of how much damage is done — to patients, to payers, and to every legitimate company in this industry — when billing is used as an instrument of fraud rather than a mechanism for accurate reimbursement. The $703 million figure is not an abstraction. It represents stolen patient identities, fabricated documentation, and money extracted from a healthcare system that is supposed to serve people who need care.
XMB was built on the opposite principle. We exist to help legitimate healthcare practices get paid accurately for services they actually provided — not a dollar more, not a dollar less. Our certifications, our documentation standards, our refusal to represent clients we cannot verify, and our HIPAA-compliant data handling are not marketing checkboxes. They are the operational infrastructure of a billing company that believes accuracy and integrity are the same thing.
We are transparent about who we are, where we operate, and how every claim we submit is generated. We welcome scrutiny. Any provider considering a billing partnership — with XMB or with any company — should expect that level of transparency as the baseline, not the exception.
XMB's Non-Negotiable Operating Standards
The following principles are not aspirational — they are the conditions under which XMB accepts and retains every client engagement. They are not subject to client instruction or commercial negotiation.
-
1We bill only for services that were provided. Every claim is supported by a clinical encounter, a legitimate provider order, and documentation in the patient record. We do not submit claims for services not rendered, not ordered, or not medically documented — regardless of reimbursement opportunity or client instruction.
-
2We do not fabricate, alter, or substitute documentation. If documentation is insufficient to support a submitted code, we flag the deficiency and return to the provider for correction. We never create, modify, or supplement records to support a claim the documentation does not independently support.
-
3Patient data is used exclusively for the purpose for which it was provided. PHI is accessed solely to perform contracted billing services for the specific provider who authorized access. We do not sell, share, aggregate, or repurpose patient data. Every engagement is governed by a signed Business Associate Agreement.
-
4We do not pay or receive kickbacks of any form. XMB's compensation is a service fee agreed contractually with the provider. No referral fees, revenue-share arrangements, or marketing commissions tied to claim volume — no arrangement that could constitute a kickback under the Anti-Kickback Statute.
-
5We will not represent clients whose structure we cannot verify. XMB conducts due diligence before any engagement. We do not accept anonymous clients, entities with nominee ownership structures, or organizations that cannot provide verifiable licensure, credentialing, and operational documentation.
-
6We apply the correct code — not the highest-paying code. Our certified coders select the CPT, HCPCS, and ICD-10 codes that most accurately represent the documented service. Upcoding is a federal crime. Our CPMA-certified compliance oversight exists to prevent it.
-
7We are audit-ready at all times. Every claim is traceable to its source documentation, coding rationale, and submission record. Our clients are prepared for MAC ADR requests, OIG audits, and payer recoupment reviews before those events occur — not in response to them.
PHI, Access Controls, Accountability & Quality — Six Direct Answers
The $703 million fraud exploited the absence of answers to six questions that every billing operation should be able to answer clearly and in writing. XMB answers each one below — not in generalities, but as specific operational facts about how this company functions.
PHI access at XMB is granted on a strict need-to-know basis, limited exclusively to personnel directly involved in the billing workflow for the specific provider whose patient data is involved. Access is never blanket, never organization-wide, and never shared across unrelated client accounts.
The individuals with PHI access in any XMB engagement are: the assigned billing specialist for that account; the quality review coder who performs pre-submission claim review; the denial management specialist who accesses specific denied claims to prepare appeals; and Muhammad Tayyab, CPC, CPB, CPMA in a supervisory and audit capacity. No marketing personnel, no sales staff, no personnel working on a different provider's account, and no third parties have access to any client's PHI.
PHI access at XMB is governed by four layers of control, each independently enforceable:
- Business Associate Agreements (BAAs): Every contracted provider executes a BAA before any PHI is shared. No engagement begins and no data changes hands without a signed BAA on file.
- Role-based access restriction: Staff access is scoped to the specific account and function assigned. A biller working on one provider's account does not have access to any other provider's data. Access is provisioned per engagement and deprovisioned when assignments change.
- Encrypted transmission only: All patient data transferred between providers and XMB is transmitted using encrypted channels. Unencrypted email transmission of PHI is prohibited.
- No local PHI storage: XMB does not retain downloaded copies of patient records on local devices. All PHI remains within the provider's practice management or billing system, accessed through secure credentials only.
Every billing workflow at XMB has a named, credentialed person accountable for its outcome. Accountability is not distributed to "the team" — it is assigned to an individual at each stage:
- Charge capture and entry: Assigned billing specialist — accountable for accurate entry from the provider's clinical documentation
- CPT and ICD-10 code selection: Assigned coder — accountable for ensuring every code reflects the documented service and satisfies payer-specific coverage requirements
- Pre-submission claim review: Quality review coder — accountable for catching modifier errors, bundling conflicts, ICD-10 gaps, and add-on omissions before transmission
- Denial management and appeals: Denial specialist — accountable for identifying root cause, preparing appeals, and resolving within 48 hours
- Compliance oversight: Muhammad Tayyab, CPC, CPB, CPMA — the CPMA credential specifically authorizes conducting medical audits and carrying compliance accountability at the engagement level
Every claim passes a mandatory pre-submission review before reaching the clearinghouse. No claim transmits without clearing all of the following:
- Procedure-to-documentation match: CPT code verified against the clinical note. Mismatches are flagged and returned for correction.
- Surface area and add-on unit verification: For wound care and other specialties requiring add-on units, measurements are reviewed against billed units. Omissions producing silent underpayment are caught here.
- NCCI bundling conflict check: Claims screened against current NCCI edit tables. Any code pair triggering automatic bundling denial is caught before submission.
- ICD-10 specificity and CPT-diagnosis alignment: Every CPT code verified against linked ICD-10 codes for coverage alignment under applicable MAC LCDs or NCDs.
- Modifier accuracy check: Required modifiers verified as present, appropriate, and supported by documentation.
- Place of service verification: POS code confirmed against where the service was actually performed.
- Prior authorization confirmation: For services requiring prior auth, the authorization number is confirmed before transmission.
Billing audits at XMB operate at three levels:
- Pre-submission claim review (every claim, every account): Described in Q4. The first audit layer — prevents errors from reaching the payer rather than catching them after denial.
- Monthly account performance audit: Every active provider account is reviewed monthly for denial rate by CARC code, clean claim acceptance rate, add-on unit capture, and revenue-per-visit trends. Denial patterns emerging across a claim batch are corrected at the workflow level, not just on individual denied claims.
- Periodic CPMA compliance audit: Conducted under CPMA authority, this audit reviews a random sample of submitted claims against source documentation to verify code selection matches what was documented and performed. This is the same review a MAC ADR or OIG audit would conduct — XMB conducts it internally first.
Errors in medical billing occur. The measure of integrity is not whether errors happen — it is what happens immediately after. XMB's response distinguishes three categories:
- Coding or billing error on a submitted claim: The claim is pulled and reviewed within 24 hours. Root cause is identified in the specific workflow step. A corrected claim is resubmitted with documentation. The workflow step is corrected to prevent recurrence. The provider is notified in writing of what was wrong, what was corrected, and what changed procedurally.
- Payer-initiated audit or ADR: XMB assumes full responsibility for the response — compiling the complete documentation package and preparing the written response on behalf of the provider. Providers are never left to respond alone to billing audits for work XMB performed.
- PHI security incident or suspected breach: HIPAA Breach Notification obligations are triggered immediately. The provider is notified within the 60-day window required. XMB conducts a documented internal investigation and provides the provider with a written incident report, supporting all required notifications to HHS or affected patients.
A Note to Healthcare Providers on Choosing a Billing Partner
The $703 million fraud was executed through U.S.-based DME companies and laboratories — entities that presumably had legitimate Medicare enrollment at some point. The scheme exploited billing infrastructure. That is not a hypothetical risk. It is a documented, prosecuted, ongoing pattern across the industry.
Every healthcare provider who delegates billing to a third party bears responsibility for understanding how that company operates. The questions every provider should ask — and that every billing partner should answer without hesitation:
- Who are the actual owners and credentialed staff making coding decisions?
- How is patient data accessed, stored, and protected — and who has access to it?
- What is the process when clinical documentation does not support the billed code?
- How does the company handle claims that exceed payer frequency limits or LCD requirements?
- What is the company's denial rate — and what does it do when claims are denied?
- Has the company or any of its principals been subject to OIG exclusion, Medicare enrollment revocation, or federal investigation?
- Can the company provide a Business Associate Agreement, proof of HIPAA compliance policies, and documentation of staff credentials?
We Can Answer Every One of Those Questions — In Writing, In Advance, and On the Record
Providers should expect the same from any billing company they trust with their revenue and their compliance exposure. Contact XMB to request our compliance documentation package, including our BAA template, HIPAA compliance policy summary, staff credential documentation, and sample monthly audit report.
About Xecta Medical Billing (XMB)
Xecta Medical Billing is the revenue cycle management division of Xecta Technologies LLC, operating under the leadership of Muhammad Tayyab, CPC, CPB, CPMA — CEO and Managing Director. XMB provides specialty-focused RCM services to independent medical practices across the United States, with particular depth in wound care, physical therapy, internal medicine, pulmonology, sleep medicine, podiatry, and SNF billing.
XMB's leadership credential stack — CPC (Certified Professional Coder), CPB (Certified Professional Biller), and CPMA (Certified Professional Medical Auditor) — reflects a commitment to coding accuracy, billing integrity, and compliance-first operations that informs every client engagement. All billing activity is conducted in accordance with CMS guidelines, HIPAA requirements, applicable MAC LCD and NCD policies, and the Anti-Kickback Statute.
XMB does not participate in — and will not knowingly facilitate — any billing arrangement involving fabricated documentation, phantom services, data obtained without patient authorization, kickbacks, or intentional upcoding. These are not policies subject to client instruction or commercial negotiation. They are the conditions under which XMB operates.
Legal Note: All facts regarding the $703 million Medicare fraud case cited in this press release are derived exclusively from publicly available official sources: the U.S. Department of Justice Office of Public Affairs, IRS Criminal Investigation Division, HHS Office of Inspector General, CMS Newsroom, and verified reporting by Medical Economics and The Media Line. All defendants are presumed innocent until proven guilty in a court of law. Xecta Technologies LLC has no affiliation with, connection to, or knowledge of any of the individuals, organizations, or entities named in the federal indictment. This press release is published for informational purposes and to publicly reaffirm XMB's compliance standards.