Medicare Advantage Audit And Enforcement: The Message From CMS Is Getting Clearer

A paradigm shift is looming in how CMS will oversee plans

I have followed Medicare Advantage (MA) and Part D program audits for twenty years now. The evolution of the Centers for Medicare Medicaid Services’ (CMS) oversight has been amazing. The agency has moved from very lax standards and inconsistent enforcement to a carefully honed machine that has evolved standards (with Special Needs Plans (SNPs) protocols still evolving) and an exceeding level of professionalism. With that comes the annual program audit and enforcement reports. True, they have been published for years. But they have gone to the next level, with slick presentation emphasizing tips and best practices as to what plans need to know to drive performance on program audits.

CMS’s latest Part C and Part D audit and enforcement report (from 2025 audits) sends a familiar — but increasingly important — message: compliance is no longer just about having the right policies. It is about proving that the organization, its systems, vendors, and delegated entities actually execute those policies correctly. These issues have been around for years, and CMS underscores the deficiencies well and where organizations continue to struggle.

I want to underscore, as CMS does, that we seem to have moved from deficiencies tied to a misunderstanding of MA rules to non-compliance rooted in operational failures, data errors, and lax oversight of delegated entities. CMS explicitly says many compliance failures stemmed from operational breakdowns rather than policy misunderstandings. And these failures translate directly into beneficiary harm.

Small data problems can become big beneficiary problems

One of CMS’s central lessons from the 2025 audits is that seemingly minor data and system errors can quickly become beneficiary access issues.

CMS identified problems involving:

  • Enrollment and eligibility processing;
  • System configuration and change management;
  • Incorrect benefit and cost-sharing configurations;
  • Part D eligibility and medication rejections;
  • Prior authorization and appeals processing; and
  • Data transfers between systems.

Some beneficiaries had coverage inadvertently deactivated when they moved between benefit packages. Weekend eligibility-file processing temporarily terminated active coverage for others. In another example, transition-eligible Part D enrollees were denied medications because a system relied on an old enrollment date rather than the current effective date.

These are not necessarily dramatic failures when viewed inside an IT department.

But from the beneficiary’s perspective, they can mean a denied prescription, an unexpected bill or a delay in care.

CMS is increasingly auditing the technology and operational infrastructure behind compliance, not simply the policy manual sitting on the compliance officer’s shelf.

Complete information important

CMS also emphasized that non-compliance can often be tied to decisions that are made without all information available or considered. Auditors identified situations where relevant clinical documentation or enrollee-specific information was not fully considered, increasing the risk of inappropriate coverage determinations and delays in access.

In the ever-evolving world of SNPs, CMS found that care coordination activities did not fully reflect an enrollee’s individual needs or incorporate all available clinical information. It emphasized that compliance with documentation requirements alone does not ensure effective care coordination. It said plans need to have a comprehensive understanding of an enrollee’s health needs and the active use of available information to identify risks, coordinate services, and address beneficiary needs. Failures in this area were found with Individualized Care Plans (ICPs), Interdisciplinary Care Team coordination.

Vendor problems are the plan’s problem

Another major theme is oversight of delegated entities. CMS is blunt: delegation does not transfer accountability. They have said this for years, but it has not yet sunk in for many plans.

Plans remain responsible for the performance of their first-tier, downstream and related (FDR) entities. And CMS found numerous examples where delegated entities did not administer benefits consistently with the plan’s approved benefit design or Medicare requirements.

That included inconsistent utilization-management edits, untimely notices and payments, incorrect appeals language, and failures to implement regulatory changes consistently across systems and vendors.

This may be one of the most important findings in the report. There can be a significant gap between what a plan says its policy is and what a vendor actually does.

A plan may have a perfectly compliant utilization-management policy. But if a delegated entity applies a different edit in production, CMS is likely to focus on the beneficiary outcome—not simply the fact that the plan’s written policy was correct.

That means delegated-entity oversight needs to move beyond contractual attestations and periodic meetings. I have always encouraged my plan clients to have best practice oversight agendas for their monthly meetings with vendors. Discussing all areas of delegation each month uncovers issues that otherwise may not be vocalized until critical non-compliance emerges. Plans should demand that vendors brief them on all aspects of the relationship each month, no matter how dull and repetitive. And thorough quality assurance and auditing of these vendors should occur frequently – claims, authorization and appeals, grievance and complaints, policy and materials, and more. Do your own secret shopping.

Plans need to know:

  • What decisions are vendors actually making?
  • Are those decisions consistent with the approved benefit package?
  • Are system edits operating as intended?
  • Are notices accurate across platforms?
  • Are regulatory changes being implemented consistently?
  • Are vendor outcomes actually consistent with the plan’s policies?

Financial and technology controls are compliance controls

The enforcement findings also demonstrate that beneficiary financial protections are becoming a major compliance vulnerability.

CMS found problems involving Maximum Out-of-Pocket (MOOP) cost accumulations, claims payment methodologies, provider payments, eligibility changes, and Low-Income Subsidy (LIS) processing. In some cases, beneficiaries continued to be charged cost sharing after reaching their MOOP limit. Retroactive LIS changes were not consistently reprocessed in the Part D world.

These problems share the same underlying issue: data moving between systems and between plans and vendors did not always produce the right beneficiary outcome.

And that is why compliance cannot live exclusively within the compliance department.

IT, claims, enrollment, finance, pharmacy, utilization management and vendor management all have a role in Medicare compliance.

The enforcement numbers tell the story

CMS imposed 14 Civil Money Penalties (CMP) and 18 violations totaling $1.54 million. The largest concentration of violations involved beneficiary cost-sharing and provider-payment issues, followed by MOOP protections, LIS processing, and Part D eligibility.

The financial consequences become more significant when beneficiary harm is involved. CMS reported that 89% of violations in the 2025 CMP actions involved financial harm greater than $100. Aggravating factors also included situations where beneficiaries lacked access to medically necessary medications or services.

The largest individual penalties included CVS Health at $753,805 and Centene at $380,785, with additional penalties imposed against organizations including Health Care Service Corporation (HCSC), UnitedHealth Group, Devoted Health and others.

Monitoring yourself can make a difference

There is another subtle but important point in the report. CMS considers whether a plan’s own monitoring and auditing identified a failure and whether the organization promptly responded to correct it and remediate affected beneficiaries. This is often done as part of Compliance Program Effectiveness (CPE). That creates a powerful incentive for plans to find their own problems. Examine in the report CMS’ discussion of using a past audit to fundamentally change how it looks at CPE. CMS used one of its program audits in 2025 to pilot a revised approach that integrated compliance discussions into the operational program areas under review.

A compliance program that discovers an issue, determines the affected population, fixes the root cause, and makes beneficiaries whole is in a very different position from one that waits for CMS to discover the problem. In other words, CMS wants plans to be their own first line of defense.

Back in my days as a Medicare operator and in my mind responsible for all regulatory and compliance failures, I practiced broad transparency with my CMS Account Manager, so much so that she once emailed me to say: “Marc, I trust what you are doing. I know you are accountable.” That was her way of saying that perhaps I was reporting too much. The point is that plans often are afraid of reporting anything except for absolute compliance meltdowns for fear of opening up some compliance Pandora’s box. But CMS wants more transparency than not. In my years they have been more forgiving than not when you practice proactive disclosure with remediations complete or inflight. It certainly helps with audits as attempts at hiding the ball too often raises suspicion on the part of CMS and deeper digging.

Prior authorization reforms raise the stakes

Beginning in 2026, CMS requires plans to render Part C prior authorization decisions within 72 hours for expedited requests and seven calendar days for standard requests. Of course, Part B and D drugs remain at 24 hours for expedited requests and 72 hours for standard requests. CMS specifically says plans should be prepared to demonstrate that they can monitor those timeframes, identify delays, and ensure systems, workflows and delegated entities are aligned. We know that plans often had timeliness issues related to the Part C timeframes.

This raises the compliance stakes considerably. Prior authorization crosses multiple operational boundaries: clinical review, utilization management, technology, provider communications, notices, appeals and delegated entities.

The new paradigm plans should adopt

Perhaps the biggest takeaway from the CMS report is that compliance organizations need to start asking different questions.

It is not whether a plan has a policy but whether its policy and operational procedures answer the following:

  • Does the system actually implement the policy?
  • Does the vendor actually follow it?
  • Can we prove that through data?
  • Are errors identified before they affect beneficiaries?
  • Are we monitoring outcomes—not just process completion?
  • Are delegated entities applying the benefit consistently?
  • When something goes wrong, are we fixing the root cause or merely correcting the individual case?
  • And if something does go wrong, was it all documented, including what was done to protect the beneficiary, and considered to be reported to CMS?

CMS is pushing AI and that raises the ante too

CMS has also indicated that it will make greater use of existing data in its audit processes, increasing the importance of accuracy, completeness, and integrity in data submitted to CMS. That has always been the threat, but AI analysis across huge data sets makes that threat real now. And AI makes it such that compliance actions are no longer tied to audits performed every couple of years. Ongoing surveillance could mean CMS knocks on the door much more frequently to examine an issue. And AI and analysis means that a lot of the data analysis that was done just before the audit and during the audit can now be done much more swiftly, focusing the light more and more on actual cases of non-compliance, correction actions taken, and beneficiary impacts. CMS emphasized this last point in the report.

That may ultimately be the most important message in this year’s report. The next generation of MA and Part D compliance is going to be about operational performance. Plans that cannot connect policy with systems, vendors, data, and outcomes may discover huge compliance fines around the corner as a compliant policy is no longer enough.

And, more importantly, as prior authorization requirements tighten and CMS increases its use of data analysis to determine beneficiary impact, the distance and time between an operational problem and an enforcement action may get considerably shorter.

#medicareadvantage #partd #compliance #regulation #programaudits #priorauthorization

— Marc S. Ryan

Leave a Reply

Your email address will not be published. Required fields are marked *

Available Now

$30.00