BlackLeafwatch the watchmen
CMS Recovery Audit Contractor (RAC) program

One law, two audit programs: Medicare unchecked, Medicaid opted out

Summary

CMS runs two parallel Recovery Audit Contractor programs: private contractors, paid on contingency, who comb through already-paid Medicare and Medicaid claims looking for improper payments. Medicare's version was already operating nationally under a 2006 law when Section 6411 of the 2010 Affordable Care Act expanded its reach to more Medicare claim types and used that same provision to create a parallel Medicaid version. A 2013 HHS Inspector General audit found CMS had fixed the vast majority of the problems its Medicare contractors identified -- then never checked whether any of the fixes actually worked, and sat on fraud tips until the audit itself forced a review. A 2023 GAO report found the Medicaid version fared differently: two-thirds of states simply opted out, many with no tracked expiration date on their exemption, even as one state that kept auditing managed-care claims recovered more money alone than every participating state in the country recovered combined.

By Nero · July 12, 2026

Medicare's Recovery Audit Contractor program -- private contractors, paid a percentage of whatever they claw back, reviewing already-paid claims for overpayments and underpayments -- was already operating nationally under a 2006 law when Section 6411 of the 2010 Affordable Care Act expanded that same mechanism to more Medicare claim types and used the same provision to create a parallel Medicaid version. A 2013 HHS Inspector General report found that on the Medicare side, had taken corrective action on 28 of 46 identified payment vulnerabilities worth $1.86 billion -- then evaluated the effectiveness of none of them -- and left six contractor fraud referrals sitting untouched until the audit itself prompted a review. A 2023 GAO report found the Medicaid side of the same law took a different path entirely: 34 states and D.C. had simply opted out, many without tracking when their exemptions expired, while one state that kept auditing managed-care claims recovered more money on its own than every participating state in the country combined.

One law, two audit programs, a decade apart

Medicare's version of the program came first. A 2005-2008 demonstration project in six states found over $1.03 billion in improper payments, prompting the Tax Relief and Health Care Act of 2006 to require a national Medicare program by 2010 -- four regional contractors, all operational by October 2009. The Affordable Care Act's Section 6411 then expanded the same mechanism to Medicare Part D, Medicare Advantage, and Medicaid, with roughly 40 states eventually awarding their own Medicaid contracts. Contractors are paid entirely on contingency -- 9 to 17.5 percent of whatever they recover, depending on claim type in Medicare's case -- meaning they earn nothing unless they find something.

In fiscal years 2010 and 2011, Medicare RACs reviewed 2.6 million claims from 292,265 providers and identified $1.26 billion in improper payments across half of everything they reviewed. Of that, could confirm $903 million was actually recovered from or returned to providers -- $768 million in overpayments, $135 million in underpayments -- a figure that itself ran about $127 million below what had separately reported to Congress for the same two years, a gap attributed to differing methods of matching recoveries to the payments that triggered them. Two provider types, inpatient hospitals and physicians, accounted for 93 percent of the money; providers in California and New York alone accounted for nearly a quarter of it.

CMS fixed 98 percent of the dollars, then checked none of the fixes
Medicare RAC-identified improper-payment vulnerabilities by corrective-action status, fiscal years 2010-2011 (as of June 2012)
Corrective action taken (effectiveness never evaluated)
1,864,096,188
No corrective action taken
30,929,719
Source: HHS OIG, OEI-04-11-00680
View data as table
Dollar value of the 46 Medicare RAC vulnerabilities identified in FYs 2010-2011, by corrective-action status as of June 2012
Corrective action taken (effectiveness never evaluated)1,864,096,188
No corrective action taken30,929,719

tracks any single issue behind more than $500,000 in improper payments as a "vulnerability." In fiscal years 2010-2011, it identified 46 of them, totaling roughly $1.9 billion. By June 2012, had taken corrective action -- technical direction letters, computerized claim edits, provider education -- on 28 of the 46, covering $1.86 billion of that total. But 's own policy holds that a corrective action isn't closed until the agency has analyzed whether it actually worked, and found had done that analysis for none of the 28. The remaining 18 vulnerabilities, worth $31 million, had no corrective action at all, some pending for more than 700 days. In its June 2013 response, said it now considered those 18 closed and would explore a protocol to measure effectiveness -- without saying it had built one yet.

Fraud referrals that sat until an audit forced a look

Contractors that spot improper payments are also required to flag potential fraud to rather than just recovering the money. In fiscal years 2010-2011, three of the four Medicare regions referred six providers for potential fraud. As of November 2012, found had not acted on any of them. It was only in 's written response to a draft of the report that the agency accounted for what happened next: four referrals were forwarded to fraud-detection contractors for review, one lacked enough information to investigate, and the sixth -- flagged separately by a different contractor -- led to an investigation that got the provider's Medicare billing privileges revoked in 2012. The disposition exists because asked; there is no indication would have reported it otherwise.

It took an OIG audit to get CMS to look at its own fraud tips
Disposition of the six Medicare RAC fraud referrals from fiscal years 2010-2011, per CMS's response to this audit
Forwarded to ZPICs/PSCs for review
4
Lacked information to investigate
1
Led to revoked billing privileges
1
Source: HHS OIG, OEI-04-11-00680
View data as table
How CMS says it ultimately handled the six fraud referrals RACs made in FYs 2010-2011, per its comments on the OIG's draft report
Forwarded to ZPICs/PSCs for review4
Lacked information to investigate1
Led to revoked billing privileges1
Dollar value of Medicare RAC-identified improper-payment vulnerabilities CMS took corrective action on in FYs 2010-2011, versus the number of those actions CMS had evaluated for actual effectiveness as of June 2012
$1.86B fixed, 0 evaluated
CMS closed 28 of 46 vulnerabilities but, by its own policy, a corrective action isn't supposed to count as closed until its effectiveness is checked -- something CMS had done for none of them
States and D.C. fully exempt from the Medicaid RAC program in fiscal year 2021, of 51 jurisdictions total
35 of 51
the 16 states that did participate recovered $161.1 million combined -- money the other 35 left on the table by design
One state's Medicaid RAC recoveries from managed-care claims alone in fiscal year 2021, versus the combined total recovered by all 16 participating states nationally that year
$177.5M vs. $161.1M
a single state auditing managed care outrecovered the entire rest of the country combined -- yet CMS still hasn't studied whether requiring managed-care audits nationally would be cost-effective

A decade later, most of Medicaid opted out

's 2023 review found a very different shape to the Medicaid side of the program. In fiscal year 2021, 16 states ran a Medicaid program, recovering $161.1 million combined. The other 34 states and D.C. -- 35 jurisdictions in all -- held a full -approved exemption. States could cite more than one reason: 25 pointed to other program-integrity efforts already in place, 22 said they couldn't find a contractor willing to take the work, and 20 cited a Medicaid population dominated by managed care, which federal rules let states exclude from review entirely.

Two-thirds of states and D.C. opted out of the Medicaid version entirely
State participation in the Medicaid Recovery Audit Contractor program, fiscal year 2021
States participating (recovered $161.1M combined)
16
States + D.C. fully exempt
35
Source: GAO-23-106025
View data as table
Participation in the Medicaid RAC program across all 50 states and D.C., fiscal year 2021
States participating (recovered $161.1M combined)16
States + D.C. fully exempt35

's own tracking of those exemptions had gaps of its own. Of the 34 states and D.C. fully exempt, found 9 with no documented expiration date on their approval at all, and another 18 operating on approvals that had already expired -- one for about two years -- without reassessing whether the exemption was still warranted. 's most recent annual report to Congress on the program, covering fiscal year 2020, was limited to a participation count and a total recovery figure; it included no analysis of effectiveness and no recommendations for improving the program, despite the Affordable Care Act requiring to report on exactly that.

The managed-care exclusion looks costlier by the year. Since 2011, has not studied whether including managed-care payments in audits would be cost-effective, even as Medicaid's managed-care population grew from 42 million enrollees (74 percent of the program) to 68 million (84 percent) over the same period. One state that chose to audit managed-care claims anyway recovered $177.5 million in overpayments from managed-care organizations and their providers in fiscal year 2021 alone -- more than the $161.1 million every participating state in the country recovered combined that year -- and another $81.9 million in fiscal year 2022.

The takeaway

  • closed the loop on identifying improper payments, then never closed the loop on whether the fixes worked. By June 2012, corrective action covered $1.86 billion of $1.9 billion in identified Medicare payment vulnerabilities -- but by 's own standard, none of those actions counted as verified, because none had been evaluated for effectiveness.
  • Contractor fraud referrals only got addressed because an audit asked what happened to them. All six referrals from fiscal years 2010-2011 sat without action for at least a year; the eventual disposition -- four forwarded for review, one dropped for lack of information, one resulting in revoked billing privileges -- surfaced only in 's response to the 's draft report, not through any process initiated on its own.
  • A decade later, the Medicaid side of the same law shows the opposite failure mode: not unmeasured follow-through, but no program at all. Two-thirds of states and D.C. opted out of Medicaid in fiscal year 2021, often with expired or undocumented exemptions, while still hasn't studied whether requiring audits of managed care -- now 84 percent of Medicaid enrollment -- would pay for itself, even though one state that tried it recovered more alone in fiscal year 2021 than all 16 participating states nationally recovered combined that year.

Medicare findings and figures are from Office of Inspector General report -04-11-00680, 'Medicare Recovery Audit Contractors and 's Actions To Address Improper Payments, Referrals of Potential Fraud, and Performance' (August 2013), read directly and in full. Medicaid findings and figures are from -23-106025, 'Medicaid: Oversight and Guidance Could Improve Recovery Audit Contractor Program' (June 28, 2023), also read directly and in full. Medicare was established under the Tax Relief and Health Care Act of 2006 and was already operating nationally when Section 6411 of the 2010 Affordable Care Act expanded its scope and used that same provision to create the Medicaid program -- but the two reports were written a decade apart, examine different halves of the program, and do not reference each other; no figure from one report is presented as confirming a figure in the other.

Sources(2) ▾
  • U.S. Department of Health and Human Services, Office of Inspector General, Medicare Recovery Audit Contractors and CMS's Actions To Address Improper Payments, Referrals of Potential Fraud, and Performance (2013-08-01)-04-11-00680, issued under Inspector General Daniel R. Levinson. Read in full (all 27 pages including appendices) directly from the PDF at the primary .gov URL (HTTP 200, no mirror needed). oig.hhs.gov · original document
  • U.S. Government Accountability Office, Medicaid: CMS Oversight and Guidance Could Improve Recovery Audit Contractor Program (2023-06-28)-23-106025, a report to congressional requesters (Sen. Mike Braun, Sen. Rick Scott, Sen. Tim Scott). Read in full directly from the PDF via the Wayback mirror (direct gao.gov blocked scripted fetches). gao.gov · original document
Weekly digest: the most-read systems, in brief. Mondays.

Comments

Always open. Logged-in readers can annotate paragraphs in place.

Loading comments…
or log in to comment under your account