How University Health Prevented Impending Fraud in One Day with ProviderTrust

Fraud comes in all shapes and sizes in the healthcare industry.

Just ask Frank Estala, Senior Compliance Auditor at University Health in San Antonio, Texas, who’s put his criminal justice degree to work investigating instances of fraud, waste, and abuse in healthcare for decades.

Most recently, Mr. Estala got to the bottom of a case involving an individual who used fabricated licensure and a false identity to secure a job as a chemical dependency counselor. Follow along for the full story, including how this fraudulent provider’s real identity was exposed just in time, a week before he had a chance to interact with any patients.

ABOUT OUR CLIENT

University Health is an award-winning, nationally recognized public health and hospital system with a network of outpatient healthcare centers. Established as one of the nation’s first charity hospitals in 1917, University Health maintains a strong mission to provide compassionate, high-quality care.

CHALLENGE / SOLUTION

THE CHALLENGE

As the only academic medical center and Level I trauma center for both adults and children in the region, University Health has always taken the right precautions to ensure patient safety. That includes an exclusion monitoring program that covers about 12,800 employees and 7,300 vendors.

Before partnering with ProviderTrust, University Health engaged an independent consultant for exclusion monitoring. Though this setup checked the regulatory boxes, Mr. Estala had doubts about whether it was the most accurate method, given the disconnected nature of federal and state exclusion data primary sources.


THE SOLUTION

University Health and ProviderTrust’s partnership began as so many healthcare relationships do—at a conference. After learning about ProviderTrust’s data enrichment strategy, Mr. Estala began to explore ProviderTrust as the exclusion monitoring vendor of choice for University Health, as ProviderTrust's proprietary platform would provide a robust range of data capture for exclusion monitoring.

“What I explained to the rest of the hospital staff is that you have to be careful with exclusions,” says Mr. Estala. “If you have an excluded California provider and they decide to practice in Florida, it’s going to take about a year for that exclusion to show up [on the OIG LEIE]. But ProviderTrust follows that in real time from state to state.”

ProviderTrust’s ability to give full transparency into an employee’s exclusion status across each of the 50+ federal and state exclusion sources, plus the added security of data enrichment to connect data points from each source, offered a high level of visibility and risk reduction. With Mr. Estala and the rest of the team on board, ProviderTrust’s contract for comprehensive exclusion monitoring of employees and vendors officially kicked off in March 2025.

THE RESULTS

It’s not unusual for new ProviderTrust clients to learn about exclusions that their previous vendor wasn’t able to find, sometimes for months or years on end. In the case of University Health, the partnership began just in time to prevent a fraudulent “provider” from interacting with patients.

Just a month into the partnership, on April 29, University Health received a match alert for an employee’s Social Security (SSN) on the Social Security Death Master File (SSDMF). This individual, however, was very much alive—and currently at work.

As soon as the alert came in, Mr. Estala began a comprehensive investigation. The SSDMF match started a trail of clues that led Mr. Estala to realize that this individual had used an older relative’s SSN as if it were their own. That relative had just passed away in March, triggering the SSDMF match.

Upon closer inspection, other holes in this individual’s story emerged. Discrepancies between their resume and employee record in PeopleSoft, their HRIS, revealed that—on top of the SSN falsification—this individual’s license could not be properly verified.

Fortunately, this individual was still in training and therefore hadn’t interacted with any patients. They'd been hired as a chemical dependency counselor with a set of false credentials that were so well-disguised, they made it through the extensive hiring process.

In fact, they would have begun to see patients the very next week if this SSDMF issue hadn’t rung alarm bells. Armed with this information, University Health suspended and then terminated the individual in question within just a day of learning about the SSDMF match.

In addition to preventing any danger this person could have posed to patients, Estala calculates that University Health saved $300,000 in potential loss of revenue, civil fines, and penalties.

This reinforced the University Health team's understanding of the importance of organization-wide data integrity and transparent communication between departments. Now, University Health can move forward from the situation with clear processes for the future and the knowledge that their patients are protected by the power of ProviderTrust’s data—plus Mr. Estala’s investigative skills.

Want to see what ProviderTrust could uncover about your organization?

Get in touch today.

Loading...

Property of ProviderTrust, Inc. | 2026 All Rights Reserved.