Close

Stay informed

Drop us your email and we’ll keep you up-to-date on Medicaid issues.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Blog Post ·

Building on What Works in Medicaid Program Integrity

Federal and state governments have shared interest in supporting Medicaid programs with enhanced and new federal-level tools including an updated and modernized national provider identifier initiative, national view of claims and provider data, service-specific toolkits, and vetting of information technology solutions.

This is a watershed time for the Medicaid program. Medicaid celebrated its 60th anniversary in 2025 and, as has been typical over the history of the program, remains the subject of considerable healthy discussion and debate: viewed positively by the American public and the people whom it serves, but also a program whose expanded footprint, cost trends and increasing share of both the federal budget and state general fund budgets is driving attention at the federal and state level. Reflecting those concerns, the proponents of the Medicaid provisions in the One Big Beautiful Bill Act/Working Families Tax Cut Act (OBBBA/WFTCA) included significant changes to Medicaid eligibility in the form of work and community engagement requirements and cost sharing provisions, accountability features around program integrity, and new guardrails on the means through which states and territories make up their financial share of program costs. Related, the Centers for Medicare and Medicaid Services (CMS) has launched an all-of-agency anti-fraud initiative and has also issued policy guidance intended to interpret and operationalize provisions of the OBBBA/WFTCA.

In the context of those priorities, state Medicaid programs and their partners in state government are maximizing longstanding program integrity strategies around timely and accurate eligibility determinations, provider screening and revalidation, utilization management, data analytics, use of technology, and partnerships with managed care organizations (MCOs) to prevent, intercept and remedy fraud. Layering on these extensive efforts, federal and state governments have shared interest in supporting Medicaid programs with enhanced and new federal-level tools including an updated and modernized national provider identifier initiative, national view of claims and provider data, service-specific toolkits, and vetting of information technology solutions. Braiding these complementary strands of work has great potential to ensure that Medicaid members receive the health care services that they need and that federal and state funds are expended efficiently and appropriately. To accomplish that, however, states must continue to be able to rely on the federal government to:

  • cover matching funds, administrative costs and funds needed to operate Medicaid Fraud Control Units (MFCUs);
  • identify opportunities to provide comprehensive affiliation, ownership, and related-party interest information about Medicare and Medicaid providers, including, as relevant, for Medicaid supplemental payments; and
  • provide high quality, well-vetted nationwide data on the claiming patterns and practices of bad actors.

Related, it would be of great benefit to Medicaid programs for the federal government to identify opportunities to scale IT solutions across multiple states, as opposed to relying on state-by-state, first-dollar spending through various vendors.

Continuing to Amplify and Accelerate Historically Successful State Strategies

State and territory Medicaid programs continue to build on the significant work they have historically done through both near and longer-term strategies.

Eligibility processes

Since the program’s inception, a core component of Medicaid program integrity has been to ensure that eligibility determinations and renewals are conducted consistent with federal and state law and regulations. This is not new work. State Medicaid programs are building on an extensive portfolio of strategies designed to increase the accuracy and accountability of eligibility and renewal determinations that they launched during “unwinding” of COVID-19 public health emergency coverage requirements. This includes lean process reviews of eligibility systems, increased use of ex parte/automated means of adjudicating eligibility through reliable data sources, and use of artificial intelligence (AI). Illustrating progress in this area, the latest publicly reported month of Medicaid eligibility data (April, 2026) reveals that of the 5.8 million individuals due for renewal, 68% had their coverage successfully renewed and 47% of those renewals were done via ex parte.

Over the past year, states have built on that important base of work through:

  • extensive preparatory systems and member engagement work to implement new eligibility features of the OBBBA/WFTCA and related CMS rulemaking, including the significant changes in eligibility based on immigration status that will become effective October 1 as well as the work and community integration requirements that must be implemented by Medicaid expansion states on January 1, 2027;
  • continued attention to improving rates of ex parte adjudication, especially in light of the reliance of OBBBA/WFTCA work and community engagement requirements on automated determinations of whether an individual is subject or not to the requirements, and if subject, whether the individual has met them;
  • eligibility audits by state inspectors general/state auditors; and
  • attention to reducing Payment Error Rate Measurement (PERM) findings.

Provider credentialing, enrollment and re-enrollment processes

Medicaid programs have historically used their own screening tools along with federal data sources (the Data Exchange System, which provides access to the Social Security Administration’s Death Master File and the Medicare Exclusion Database; the Office of the Inspector General’s List of Excluded Individuals & Entities (LEIE)) to ensure that providers are properly credentialed and eligible to enroll as Medicaid performing providers, as well as re-enrolling providers every five years. This has involved stratification of the risk-level of the potential provider (limited, moderate, high) and extensive process steps including:

  • obtaining required disclosures regarding ownership and criminal convictions, using the federal data hubs and other sources, as well as confirming that the provider meets requirements for their service type;
  • conducting a site visit at the provider’s office and confirming that the information that the provider has supplied is accurate; and
  • conducting fingerprint-based criminal background checks.

Arising out of concern about trend rates in a number of specific, Medicaid-funded services (e.g., Applied Behavioral Analysis, ABA, for people with autism spectrum disorder (ASD) and others for whom it is determined to be medically necessary), the CMS Center for Program Integrity (CPI) recently required all states to submit two-year plans to revalidate all “high-risk” providers, while giving them latitude to define how that term would be applied at the state level. All states have completed and submitted those plans and these are key themes among them:

  • States are building on core federal requirements for revalidation of high-risk providers, while tailoring their provider revalidation plans to address state-specific program integrity concerns in their provider networks. Many states are continuing to rely on the Medicare definition of high risk. This has informed focus on categories of service including durable medical equipment (DME), non-emergency medical transportation (NEMT), personal care services, hospice and home health agencies. States have also proposed specific approaches for personal care services, providers of ABA services, doulas, community health workers (CHWs), peers, and substance use disorder treatment services.
  • As is permitted under federal law, Medicaid programs are continuing to rely on Medicare provider screening for a significant portion of their providers. This enables states to prioritize use of their staff and contractor resources for providers that exclusively participate in Medicaid (e.g., home and community-based services (HCBS) for older adults and people with disabilities).
  • Most states are only revalidating high- and moderate-risk providers in the two-year period, but a subset of states are planning to 1) revalidate all providers; and/or 2) require providers without a National Provider Identifier (NPI) to obtain one (Wyoming and Massachusetts). Notably, Minnesota has already completed a full provider revalidation cycle in context of its negotiations with the federal government and has shared advice on this work with peer states.
  • Finally, states articulate in their plans how they intend to partner across state government (e.g., with their MFCU and law enforcement) as well as with contracted partners (vendors, MCOs) to execute this work.

Over and above plans to prioritize high-risk providers, states are also building additional features into their provider enrollment processes. Examples of this include:

  • California exceeding federal minimum standards by requiring providers to report changes in ownership, service location, or practice sites within 35 days — events that automatically trigger targeted off‑cycle revalidation activities;
  • Nevada Medicaid’s use of biometric technology during provider enrollment;
  • Nebraska’s adoption of a strong developmental disabilities personal care assessment tool;
  • Tennessee’s program integrity strategy for self-directed services; and
  • DC’s requirement for NPIs for all rendering providers, including those that offer HCBS.

NAMD has also been active in this area. A notable example of this is developing important new partnerships with national peer organizations including the National Association for Medicaid Program Integrity (NAMPI) and the National Association of Medicaid Fraud Units (NAMFCU). This has enabled NAMD to share information with its state and territory members on NAMPI initiatives including a state exclusion project that is focused on preventing bad actors — especially those who may not appear on federal exclusion lists (e.g., billers, consultants, authorized signers) – from migrating among states.  Individual states are also convening partners for this purpose, notably including Ohio’s Program Integrity Groups, which include a range of partners including the Ohio MFCU, sister state departments and managed care plans.

Many states are also using provider suspensions and targeted provider moratoria to permit closer examination of patterns in provision of high-risk services.  Key examples of this include Florida’s moratorium on new DME providers and New York’s enrollment moratorium for laboratory; durable medical equipment; prosthetics, orthotics, and supplies (DMEPOS); ABA; pharmacy; Licensed Home Care Services Agencies (LHCSA); and managed long-term care plan providers.

Utilization management

All Medicaid programs implement an array of utilization management (UM) strategies, including prior authorization, diagnostic criteria, and caps on type or frequency of services, and implement those standards through publication of provider guidelines and system edits that intercept non-compliant claims prior to payment. Many state Medicaid programs have recently engaged in detailed review of service definitions and UM standards for high-risk services including ABA and personal care services. States have also been sharing promising practices with one another. An important example of this is Texas’ and North Carolina’s strong UM policies around ABA.

Medicaid managed care organization (MCO) provisions

Medicaid MCOs nationwide have historically used compliance teams (often known as Special Investigation Units), analyses of claims and encounter data, chart reviews, billing assessments, provider site visits, enhanced provider screening, and referrals to state MFCUs to address provider fraud. Expanding on this significant body of work:

  • states have been sharing promising practices with one another, notable examples of which include Tennessee’s rigorous contract requirements and “Voice of the Customer” performance sessions and 360° reviews in New Jersey and Virginia;
  • states have also been reviewing Managed Care Program Annual Report (MCPAR) reports to yield insights on relative activation of plans in making fraud referrals; and
  • MCOs have been activating around areas of focus for state Medicaid programs, including more stringent review and vetting of providers of the high-risk services that are referenced above, analyses of trends in claiming for ABA and personal care services, and review of trend data to examine its proportionality to trends in census served by the program.

Systemic review and audits, using data analytics and innovative new technology solutions

Medicaid programs analyze their claims to identify patterns and outliers that signal potential areas of provider fraud and abuse. They also use post-payment audits that yield findings of inadequate documentation as well as improper billing, and result in recoupment of claims paid. Many states also contract with recovery audit contractors that are incentivized on a contingency basis for identifying fraud.

Layering on this, states have been adopting additional promising practices with the intention of moving from a “pay and chase” to a “caught and stopped” orientation. Notable, non-exclusive examples include:

  • the District of Columbia’s use of various data sets, including claims data and Electronic Visit Verification (EVV) Global Positioning System (GPS) data, and data visualization tools including outlier dashboards that allow program integrity staff to quickly identify unusual billing patterns;
  • Alabama’s Outlier Dashboard and use of AI tools; and
  • Arizona’s enhanced prepayment review for providers with unusual billing patterns, high per-member cost or prior fraud, waste and abuse (FWA) referrals as well as AI-informed data analytics through the Alivia Analytics FWA finder.

Medicaid Fraud Control Units (MFCUs)

MFCUs are responsible for investigating referrals related to fraud and patient abuse or neglect by Medicaid-enrolled providers and assessing which of those should be pursued for criminal prosecution and/or civil penalties. In its Medicaid Fraud Control Unit Fiscal Year 2025 Annual Report, the Office of the Inspector General (OIG) detailed that:

  • MFCUs recovered $4.64 for every dollar spent by States and the Federal Government.
  • Combined recoveries from criminal and civil cases totaled almost $2 billion for FY 2025.
  • Criminal recoveries from convictions totaled $1.3 billion and civil recoveries totaled $706 million.
  • MFCUs also reported 674 civil settlements and judgments for FY 2025.

While MFCUs are ramping up their level of activity, a current challenge is that the federal government appears to be setting a more rigorous bar for renewal of certification and continued federal funding of these units, resulting in two cases of defunding (Hawaii and New York). Given that MFCUs rely on federal funding to support their fraud investigations, it would be helpful for the federal government to provide active technical assistance to states in process of renewal as well as to identify proactive steps that states can take to align their staffing structures and operations with federal expectations.

Staff training on program integrity

Medicaid agency program integrity staff receive training from the Medicaid Integrity Institute (MII) to continuously enhance their strategy and operations. Recognizing the reality that many states have limited funding for staff travel, CPI has announced that MII is being made available on a virtual basis, which will support many more state staff in attending.

Support Medicaid Programs with Federal-Level Tools 

CMS has helpfully activated enhanced and new federal-level tools including:

  • launch of an updated and modernized National Provider Identifier number initiative that aims to enhance the capacity of that system to vet and enroll valid providers and screen out bad actors who have committed fraud or otherwise failed to meet requirements under a publicly-funded health care program;
  • fulfilling the OBBBA/WFTCA mandate to strengthen and better automate the Public Assistance Reporting Information System (PARIS), which is the central means of determining whether a person is enrolled in more than one Medicaid program at any given time and has historically been a very manual, spreadsheet-based process;
  • production of a new Medicaid Emerging Vulnerability Intelligence and Actions (MEVIA) platform, a new data and analytic resource that has been rolled out to all Medicaid programs with the goal of enhancing their capacity to identify emerging trends and outliers; and
  • issuance of a detailed toolkit to support states in effectively defining, adopting and implementing assessment and utilization management strategies, and ensuring program integrity for ABA services for people with ASD, which has been very positively received.

Medicaid programs are also eager to provide operational feedback on and partner with CMS in implementing further federal guidance that is expected to be released in the Fall, including:

  • model program integrity provisions that will be required for all Medicaid authorities, including state plan, waiver and demonstration pathways;
  • Comprehensive Regulations to Uncover Suspicious Healthcare-related (CRUSH) rulemaking, which is currently slated on the Unified Regulatory Agenda as having an October 1 release date; and
  • report on CMS’ initiative around testing program integrity IT solutions through 60- to 90-day sprints, including what worked and what can potentially be taken up or scaled by states to enhance their current approaches.

Conclusion

States and the federal government have vital roles in safeguarding the integrity of the Medicaid program as both have taxpayer dollars to protect. As CMS concurrently pursues regulatory enforcement as well as the state/territory partnership initiatives detailed above — we encourage close connections with Medicaid agencies to ensure that those actions: 1) are informed by Medicaid agencies’ on-the-ground experience with program integrity risks and strategies; and 2) effectively advance existing state-level efforts, including use of corrective action plans that are mutually negotiated by the involved state and CMS. Related, states and territories must continue to receive federal match, administrative, and MFCU funding to underwrite the costs of staff and technology needed to combat fraud in the Medicaid program. All of these elements are key to productive and meaningful outcomes for the people whom state Medicaid programs serve and the taxpayers whom they protect.

 

Related resources

Stay Informed

Drop us your email and we’ll keep you up-to-date on Medicaid issues.