By RICARDO ALONSO-ZALDIVAR (AP)
WASHINGTON — They don't seem that interested in hot pursuit. It took private sleuths hired by Medicare an average of six months last year to refer fraud cases to law enforcement.
According to congressional investigators, the exact average was 178 days. By that time, many cases go cold, making it difficult to catch perpetrators, much less recover money for taxpayers.
A recent inspector general report also raised questions about the contractors, who play an important role in Medicare's overall effort to combat fraud.
Out of $835 million in questionable Medicare payments identified by private contractors in 2007, the government was only able to recover some $55 million, or about 7 percent, the report found.
Medicare overpayments — they can be anything from a billing error to a flagrant scam — totaled more than $36 billion in 2009, according to the Obama administration.
President Barack Obama has set a high priority on battling health care fraud and waste, hoping for savings to help pay for the new law covering millions now uninsured.
Medicare's private eyes don't seem to be helping much.
Sen. Charles Grassley, R-Iowa, questions whether taxpayers are getting good value from for-hire fraud busters. His office, which is investigating the contracting program, obtained Medicare data for the last four years on how long it took to refer cases to federal agents.
"Medicare is already a pay-and-chase system when it comes to fraud, waste and abuse," said Grassley. "Providers are paid first, then questioned if there's a problem. Add to that mix contractors who sit on cases of ongoing fraud when they should be referring them to law enforcement, and you have a recipe for disaster."
As ranking Republican on the Senate panel that oversees Medicare, Grassley is trying to find out why it takes the contractors so long, and how much the government is currently paying the companies. In 2005, taxpayers paid them $102 million.
At least seven private companies Medicare calls "Program Safeguard Contractors" are working to detect fraud, part of a program that dates to the late 1990s. They oversee specific areas of jurisdiction, and some have more than one contract with Medicare.
The contractors investigate allegations of wrongdoing, acting as scouts for the government's criminal investigators. And they're also supposed to conduct "proactive" analysis to spot emerging fraud trends. For instance, they can use sophisticated computer models to scan millions of Medicare records for suspicious patterns to identify dishonest providers.
In practice, their performance has been uneven. The contractors have widely different track records. One identified $266 million in overpayments in 2007, while another found just $2.5 million, the Health and Human Services inspector general said in May.
Earlier, the inspector general found gaping differences in the number of new cases the contractors generate for law enforcement. Some had hundreds of cases, while others were in the single digits. Most were doing a poor job at spotting new fraud trends, with "minimal results from proactive data analysis," the inspector general concluded.
The Obama administration says it's aware of the problem and is close to completing a reorganization of the contractors, to consolidate their work, define their jurisdictions more clearly, and help them coordinate better with claims processors and law enforcement.
The private sleuths will now be called "Zone Program Integrity Contractors" — or ZPICs for short.
"By using these new contractors that can review claims across multiple providers and benefit categories, we will be better able to identify cases of waste, fraud or abuse," said Medicare spokesman Peter Ashkenaz. "And, we will be better able to monitor both the ZPICs' overpayment and collection efforts to make sure that they are performing their own oversight responsibilities."
In fairness to the contractors, the low collection rate may not just be their fault. Investigators say that when Medicare notifies a provider about a disputed payment, the fraudulent ones often just close up shop and move on.
Copyright © 2010 The Associated Press. All rights reserved.
A blog dedicated to the anti-fraud community towards creating awareness and preventing Fraud and all related fields and activities
Wednesday, August 11, 2010
Sunday, August 1, 2010
Hack makes ATMs spew out cash


July 30, 2010
A hacker has discovered a way to force ATMs to disgorge their cash by hijacking the computers inside them.
The attacks successfully targeted standalone ATMs, but they could potentially be used against the ATMs operated by mainstream banks.
Criminals have long known that ATMs aren't tamperproof.
There are many types of attacks in use today, ranging from sophisticated to foolhardy: installing fake card readers to steal card numbers, hiding tiny surveillance cameras to capture PIN codes, covering the dispensing slot to intercept money and even hauling the ATMs away with trucks in the hopes of cracking them open later.
Computer hacker Barnaby Jack spent two years tinkering in his Silicon Valley apartment with ATMs he bought online. These were standalone machines, the type seen in front of convenience stores, rather than the ones in bank branches.
His goal was to find ways to take control of ATMs by exploiting weaknesses in the computers that run the machines.
He showed off his results at the Black Hat conference in Las Vegas, an annual gathering devoted to exposing the latest computer-security vulnerabilities.
His attacks have wide implications because they affect multiple types of ATMs and exploit weaknesses in software and security measures that are used throughout the industry.
His talk was one of the conference's most widely anticipated, as it had been pulled a year ago over concerns that fixes for the ATMs would not be in place in time. He used the extra year to craft more dangerous attacks.
Jack, who works as director of security research for Seattle-based IOActive, showed in a theatrical demonstration two ways he can get ATMs to spit out money.
Jack found that the physical keys that came with his machines were the same for all ATMs of that type made by that manufacturer. He figured this out by ordering three ATMs from different manufacturers for a few thousand dollars each. Then he compared the keys he got to pictures of other keys, found on the internet.
He used his key to unlock a compartment in the ATM that had standard USB slots. He then inserted a program he had written into one of them, commanding the ATM to dump its vaults.
Jack also hacked into ATMs by exploiting weaknesses in the way ATM makers communicate with the machines over the internet. Jack said the problem was that outsiders were permitted to bypass the need for a password. He didn't go into much more detail because he said the goal of his talk "isn't to teach everybody how to hack ATMs. It's to raise the issue and have ATM manufacturers be proactive about implementing fixes".
The remote style of attack is more dangerous because an attacker doesn't need to open up the ATMs.
It allows an attacker to gain full control of the ATMs. Besides ordering it to spit out money, attackers can silently harvest account data from anyone who uses the machines. It also affects more than just the standalone ATMs vulnerable to the physical attack; the method could potentially be used against the kinds of ATMs used by mainstream banks.
Jack said he didn't think he'd be able to break the ATMs when he first started probing them.
"My reaction was, 'This is the game-over vulnerability right here,'" he said of the remote hack. "Every ATM I've looked at, I've been able to find a flaw in. It's a scary thing."
Kurt Baumgartner, a senior security researcher with anti-virus software maker Kaspersky Lab, called the demonstration a "thrill" to watch and said it was important to improving the security of machines that can each hold tens of thousands of dollars in cash. However, he said he does not think it will result in widespread attacks because banks don't use the standalone systems and Jack did not release his attack code.
Jack would not identify the ATM makers. He put stickers over the ATM makers' names on the two machines used in his demonstration. But the audience, which burst into applause when he made the machines spit out money, could see from the screen prompts on the ATM that one of the machines was made by Tranax Technologies, based in Hayward, California. Tranax did not respond to email messages from The Associated Press.
Triton Systems, of Long Beach, confirmed that one of its ATMs was used in the demonstration. It said Jack alerted the company to the problems and that Triton now had a software update in place that prevents unauthorised software from running on its ATMs.
Bob Douglas, Triton's vice-president of engineering, said customers could buy ATMs with unique keys but generally do not, preferring to have a master key for cost and convenience.
"Imagine if you have an estate of several thousand ATMs and you want to access 20 or so of them in one day," he wrote in an email to the AP. "It would be a logistical nightmare to have all the right keys at just the right place at just the right time."
Other ATM manufacturers contacted by the AP also did not respond to messages.
Jack said the manufacturers whose machines he studied were deploying software fixes for both vulnerabilities, but added that the prevalence of remote-management software broadly opened up ATMs to hacker attacks.
Source: Sydney Morning Herald
Saturday, July 31, 2010
Satyam accounts restatement is Rs 50-cr windfall for audit firms
Mahindra Satyam may end up paying a huge fee for restatement of its book of accounts that were allegedly fudged by its former Chairman Mr B. Ramalinga Raju.
Indications are that the Hyderabad-based company will shell out close to Rs 60 crore by September when the accounts are expected to be restated.
“If you include the forensic accounting and all other payments the company has to make for the restatement, the outgo will easily be ‘north of Rs 50 crore'. With every round of delay, the costs are going up,” a top official in the know told Business Line.
Days after Mr Raju confessed to fudging the Satyam accounts, a Government-nominated board had appointed auditing firms KPMG and Deloitte to help clear the mess.
Audit issues
Due to a host of reasons ranging from the complexity of the fraud to the unavailability of key documents, the restatement has fallen behind schedule three times already with the concomitant affect of pushing up the overall costs.
The company's outgo goes up given that most audit firms charge on a man-hour basis, sources said.
Mr Vineet Nayyar, Chairman of Mahindra Satyam, referred to this at a recent press conference, when he said that the Satyam accounts restatement is “costing the company a fortune”. However, he did not provide further details
A spokesperson for KPMG said, “We do not comment on client matters.” His counterpart at Deloitte said it was now the statutory auditor for the Mahindra Satyam accounts and no longer associated with the process of account restatement.
So, how do industry watchers view this development?
“If the company is paying over Rs 50 crore for restating its accounts, just imagine what could potentially be the size of the fraud itself. I think that it is detrimental to shareholder interests,” Mr Uttam Prakash Agarwal, former President of the Institute of Chartered Accountants of India, said.
The positive part, according to him, is that it sends a message to the corporate world that cost of investing in compliance cannot be substituted with anything else
In all fairness to the audit firms, the Satyam challenge was something unparallel in accounting frauds. During the course of the process, the two accounting firms had dredged almost two terabytes of data from laptops and personal computers at Satyam. Since this information is much more than what could have been warehoused anywhere in India, it was moved to the UK till lab facilities could be created here, a recent news report said.
Source: The Hindu Business Line; By Adith Charlie, dt: July 30
Indications are that the Hyderabad-based company will shell out close to Rs 60 crore by September when the accounts are expected to be restated.
“If you include the forensic accounting and all other payments the company has to make for the restatement, the outgo will easily be ‘north of Rs 50 crore'. With every round of delay, the costs are going up,” a top official in the know told Business Line.
Days after Mr Raju confessed to fudging the Satyam accounts, a Government-nominated board had appointed auditing firms KPMG and Deloitte to help clear the mess.
Audit issues
Due to a host of reasons ranging from the complexity of the fraud to the unavailability of key documents, the restatement has fallen behind schedule three times already with the concomitant affect of pushing up the overall costs.
The company's outgo goes up given that most audit firms charge on a man-hour basis, sources said.
Mr Vineet Nayyar, Chairman of Mahindra Satyam, referred to this at a recent press conference, when he said that the Satyam accounts restatement is “costing the company a fortune”. However, he did not provide further details
A spokesperson for KPMG said, “We do not comment on client matters.” His counterpart at Deloitte said it was now the statutory auditor for the Mahindra Satyam accounts and no longer associated with the process of account restatement.
So, how do industry watchers view this development?
“If the company is paying over Rs 50 crore for restating its accounts, just imagine what could potentially be the size of the fraud itself. I think that it is detrimental to shareholder interests,” Mr Uttam Prakash Agarwal, former President of the Institute of Chartered Accountants of India, said.
The positive part, according to him, is that it sends a message to the corporate world that cost of investing in compliance cannot be substituted with anything else
In all fairness to the audit firms, the Satyam challenge was something unparallel in accounting frauds. During the course of the process, the two accounting firms had dredged almost two terabytes of data from laptops and personal computers at Satyam. Since this information is much more than what could have been warehoused anywhere in India, it was moved to the UK till lab facilities could be created here, a recent news report said.
Source: The Hindu Business Line; By Adith Charlie, dt: July 30
Thursday, July 29, 2010
Indian-American woman pleads guilty in $34 million fraud case
WASHINGTON: An Indian-American woman executive has pleaded guilty to defrauding her company of $34 million to pay for her "irrational" buying sprees and faces up to 20 years in jail on conviction.
46-year-old Sujata Sachdeva, a former Vice President of finance at Koss Corporation, pleaded guilty to all the six counts of wire fraud, for which she was charged early this year, before a Milwaukee court in Wisconsin on Tuesday.
"Ms Sachdeva recognises the harm she has caused to her employers, the company shareholders, her colleagues and her friends, but she most regrets the pain and public embarrassment she has caused to her husband, Ramesh, and their two young children," her attorney Mike Hart said.
Reading out a statement with Sachdeva standing besides him outside the Milwaukee court, Hart said she has cooperated with federal prosecutors to recover as much of the merchandise as possible to pay restitution to Koss Corporation, a headphone manufacturer.
Sachdeva has begun to address the issues that led to her conduct and accepts full responsibility for her actions, and hopes for a fair and just result, Hart said.
Facing five to 20 years of imprisonment, if convicted, Sachdeva remains free on bond pending sentencing, which is scheduled for October 22.
According to the indictment, Sachdeva authorised numerous wire transfers of funds from bank accounts maintained by Koss to pay for her American Express credit card bills.
In addition, Sachdeva used money from Koss' bank accounts to fund numerous cashier's checks, which she also used to pay her personal expenses.
Sachdeva used the money she fraudulently obtained from Koss to purchase personal items including women's clothing, furs, purses, shoes, jewellery, automobiles, china, statues, and other household furnishings.
Sachdeva also used the money to pay for hotels, airline tickets and other travel expenses for her and others; to pay for renovations and improvements to her home; and to compensate individuals providing personal services to her and her family, the indictment alleged.
According to the indictment, Sachdeva sought to conceal her fraud by directing other Koss employees to make numerous fraudulent entries in Koss' books and records to make it appear that Sachdeva's fraudulent transfers were legitimate business transactions.
Source: The Times Of India; 29.07.10
46-year-old Sujata Sachdeva, a former Vice President of finance at Koss Corporation, pleaded guilty to all the six counts of wire fraud, for which she was charged early this year, before a Milwaukee court in Wisconsin on Tuesday.
"Ms Sachdeva recognises the harm she has caused to her employers, the company shareholders, her colleagues and her friends, but she most regrets the pain and public embarrassment she has caused to her husband, Ramesh, and their two young children," her attorney Mike Hart said.
Reading out a statement with Sachdeva standing besides him outside the Milwaukee court, Hart said she has cooperated with federal prosecutors to recover as much of the merchandise as possible to pay restitution to Koss Corporation, a headphone manufacturer.
Sachdeva has begun to address the issues that led to her conduct and accepts full responsibility for her actions, and hopes for a fair and just result, Hart said.
Facing five to 20 years of imprisonment, if convicted, Sachdeva remains free on bond pending sentencing, which is scheduled for October 22.
According to the indictment, Sachdeva authorised numerous wire transfers of funds from bank accounts maintained by Koss to pay for her American Express credit card bills.
In addition, Sachdeva used money from Koss' bank accounts to fund numerous cashier's checks, which she also used to pay her personal expenses.
Sachdeva used the money she fraudulently obtained from Koss to purchase personal items including women's clothing, furs, purses, shoes, jewellery, automobiles, china, statues, and other household furnishings.
Sachdeva also used the money to pay for hotels, airline tickets and other travel expenses for her and others; to pay for renovations and improvements to her home; and to compensate individuals providing personal services to her and her family, the indictment alleged.
According to the indictment, Sachdeva sought to conceal her fraud by directing other Koss employees to make numerous fraudulent entries in Koss' books and records to make it appear that Sachdeva's fraudulent transfers were legitimate business transactions.
Source: The Times Of India; 29.07.10
Thursday, July 22, 2010
SEBI makes cell ban in dealing rooms official
MUMBAI: Most mutual funds have barred use of mobile phones in their dealing rooms to prevent front-running, though regulations didn’t require them
to do so until recently.
Last week, the Securities and Exchange Board of India (Sebi) made this ban official on the heels of its recent order, which pulled up an equities dealer at HDFC Asset Management for leaking information of its planned trades to a few other investors.
In a communication to mutual funds, the market regulator, in addition to the ban on mobile phone usage in dealing rooms, also asked asset management companies (AMCs) to record telephone calls from or into dealing rooms. Also, recorded calls by dealers should be regularly monitored by its compliance department, Sebi said.
Mutual fund officials said the practice of front-running is unlikely to cede, following the new rules by Sebi, as most AMCs already have such systems in place. “It doesn’t say anything more than what we are already doing,” said a top official with a private mutual fund.
Mutual fund officials said more steps are already in place to check front-running than what are mentioned in the circular. These include having restrictions on the rates at which dealers can place the ‘buy’ or ‘sell’ order in a day and checks on any changes in their lifestyles.
“If a dealer suddenly manages to buy a house in a plush locality or even a luxury car, then, we step up our vigilance. Similarly, we look if any particular broker talks more to a particular dealer than the fund manager...These are leads for us,” said the chief investment officer with a private mutual fund.
In a mutual fund, the practice of front-running harms unitholders, as it increases the cost of share purchases or reduces the realisations from share sale, thereby depressing returns.
Some mutual fund officials and brokers said Sebi’s emphasis to tackle front-running only in the dealing rooms is misplaced. “The focus is more on the small fish (dealers), while big sharks (some fund managers and market operators) have been let off the hook,” said a fund manager with a bank-owned mutual fund. “The profits made by the dealer (HDFC AMC) and his associates are paltry compared with what is being made outside the dealing room,” he said.
The three investors, who placed orders in the same set of stocks just before those were traded by dealer Nilesh Kapadia on HDFC AMC’s behalf, made combined profits of about `2 crore in four months, according to the Sebi order on June 17.
Brokers said fund managers, who usually buy or sell shares ahead of their employers, escape the regulatory radar by spreading their trades across various brokers. “Fund managers ensure that there is no pattern in the way any person or broker, who has been assigned to buy shares on their behalf, has done the trade,” said a broker, who is familiar with such trades. “There is no way that the regulator can catch them in the existing regulatory situation,” he said.
Source: The Economic Times
to do so until recently.
Last week, the Securities and Exchange Board of India (Sebi) made this ban official on the heels of its recent order, which pulled up an equities dealer at HDFC Asset Management for leaking information of its planned trades to a few other investors.
In a communication to mutual funds, the market regulator, in addition to the ban on mobile phone usage in dealing rooms, also asked asset management companies (AMCs) to record telephone calls from or into dealing rooms. Also, recorded calls by dealers should be regularly monitored by its compliance department, Sebi said.
Mutual fund officials said the practice of front-running is unlikely to cede, following the new rules by Sebi, as most AMCs already have such systems in place. “It doesn’t say anything more than what we are already doing,” said a top official with a private mutual fund.
Mutual fund officials said more steps are already in place to check front-running than what are mentioned in the circular. These include having restrictions on the rates at which dealers can place the ‘buy’ or ‘sell’ order in a day and checks on any changes in their lifestyles.
“If a dealer suddenly manages to buy a house in a plush locality or even a luxury car, then, we step up our vigilance. Similarly, we look if any particular broker talks more to a particular dealer than the fund manager...These are leads for us,” said the chief investment officer with a private mutual fund.
In a mutual fund, the practice of front-running harms unitholders, as it increases the cost of share purchases or reduces the realisations from share sale, thereby depressing returns.
Some mutual fund officials and brokers said Sebi’s emphasis to tackle front-running only in the dealing rooms is misplaced. “The focus is more on the small fish (dealers), while big sharks (some fund managers and market operators) have been let off the hook,” said a fund manager with a bank-owned mutual fund. “The profits made by the dealer (HDFC AMC) and his associates are paltry compared with what is being made outside the dealing room,” he said.
The three investors, who placed orders in the same set of stocks just before those were traded by dealer Nilesh Kapadia on HDFC AMC’s behalf, made combined profits of about `2 crore in four months, according to the Sebi order on June 17.
Brokers said fund managers, who usually buy or sell shares ahead of their employers, escape the regulatory radar by spreading their trades across various brokers. “Fund managers ensure that there is no pattern in the way any person or broker, who has been assigned to buy shares on their behalf, has done the trade,” said a broker, who is familiar with such trades. “There is no way that the regulator can catch them in the existing regulatory situation,” he said.
Source: The Economic Times
Monday, July 12, 2010
ICAI for compulsory Outsourcing of Internal Audit functions
Accounting regulator the Institute of Chartered Accountants of India (ICAI) has asked the government to make outsourcing of internal audit functions mandatory for companies to prevent a Satyam-like fraud from happening again.
The suggestion is part of the recommendations by a high-powered committee of ICAI to the Corporate Affairs Ministry in the aftermath of a Rs 10,000-crore scam in Satyam Computer and is intended to strengthen the internal audit system of companies.
"We have recommended that internal audit should be outsourced rather than in-house because internal audit in-house is always dependent on the management of the company. Internal audit from outside will always be better, and then it should be given to chartered accountants," ICAI President Amarjit Chopra told PTI.
The role of internal auditors came under scanner after Satyam Computer founder B Ramalinga Raju confessed to having cooked the books of the company for years. The IT firm's internal audit head S Prabhakar Gupta was arrested for his alleged role in the multi-crore fraud.
Interestingly, Satyam's internal audit team was given recognition of commitment award by the US-based Institute of Internal Auditors in 2006.
Chopra further said that since internal audit is the first check-post for any accounting fraud, due care should be taken to ensure it is conducted by the right people and independently.
"We already have 17 internal audit standards and we have asked the Government to make these standards mandatory for internal audits, whether through Sebi or through company law, so that there is standardisation of internal audit procedures," Chopra said.
The standards are benchmarks for internal auditors and are aimed at ensuring standardisation, independence and more consistency in the functioning.
They also differentiate auditor's responsibilities when it comes to complying with the law and regulations that have direct impact on financial statements as well as significant effect on the functioning of the company.
Source: Business India; July 8,2010; By Press Trust of India, New Delhi
The suggestion is part of the recommendations by a high-powered committee of ICAI to the Corporate Affairs Ministry in the aftermath of a Rs 10,000-crore scam in Satyam Computer and is intended to strengthen the internal audit system of companies.
"We have recommended that internal audit should be outsourced rather than in-house because internal audit in-house is always dependent on the management of the company. Internal audit from outside will always be better, and then it should be given to chartered accountants," ICAI President Amarjit Chopra told PTI.
The role of internal auditors came under scanner after Satyam Computer founder B Ramalinga Raju confessed to having cooked the books of the company for years. The IT firm's internal audit head S Prabhakar Gupta was arrested for his alleged role in the multi-crore fraud.
Interestingly, Satyam's internal audit team was given recognition of commitment award by the US-based Institute of Internal Auditors in 2006.
Chopra further said that since internal audit is the first check-post for any accounting fraud, due care should be taken to ensure it is conducted by the right people and independently.
"We already have 17 internal audit standards and we have asked the Government to make these standards mandatory for internal audits, whether through Sebi or through company law, so that there is standardisation of internal audit procedures," Chopra said.
The standards are benchmarks for internal auditors and are aimed at ensuring standardisation, independence and more consistency in the functioning.
They also differentiate auditor's responsibilities when it comes to complying with the law and regulations that have direct impact on financial statements as well as significant effect on the functioning of the company.
Source: Business India; July 8,2010; By Press Trust of India, New Delhi
Subscribe to:
Posts (Atom)