The Fraud Unit Got Defunded. The Referral Duty Didn’t.
HHS-OIG has decertified two state Medicaid Fraud Control Unit since June and put all fifty-three units on notice, the same week its own national review found that fraud-referral requirements for managed care organizations vary by design from state to state. Submitting a fraud referral and knowing what happens to it are no longer the same compliance question.
Two fraud units lost federal certification in two months. Fifty-one more sit under the same review standard.
In March 2026, an executive order created the Task Force to Eliminate Fraud, chaired by Vice President JD Vance. On May 13, HHS Inspector General March Bell told every state Attorney General to expect “rigid MFCU compliance” review. Hawaii’s Medicaid Fraud Control Unit lost certification in June. New York’s followed on July 1, 2026, funding suspended, corrective actions required.
“Noncompliance with your MFCU obligations can take your State’s entire Medicaid program out of compliance.” (HHS-OIG letter to state Attorneys General, May 13, 2026)
New York’s Medicaid Fraud Control Unit: the specific numbers behind the decertification
HHS-OIG cited slow case progression, an investigation backlog, and referral and tracking deficiencies. New York’s Attorney General has disputed the characterization. Hawaii’s MFCU, decertified in June, recorded no criminal indictments or convictions for Medicaid fraud from 2022 through 2025; the state responded by creating an independent Medicaid Fraud Strike Force.
The same week New York lost its unit, OIG reported the referral system itself is unevenly built
Report OEI-03-23-00340, issued July 16 and posted July 21, 2026, evaluated how all states require Medicaid MCOs to refer suspected fraud.
- Recommendation 1Require all MCOs to refer potential fraud promptly. CMS concurred.
- Recommendation 2Require state contracts to specify consequences for MCO noncompliance. CMS concurred.
- Recommendation 3Expand feedback to MCOs on referral outcomes. CMS did not formally concur or nonconcur, but said it has taken steps.
- Recommendation 4Assess federal-level actions to improve referral volume. CMS did not formally concur or nonconcur, but said it has taken steps.
Four months from executive order to a 53-unit review is not a coincidence of timing
Trade press noted that HHS and CMS announced more than $1 billion in additional Medicaid funding withheld from California and Minnesota on the same day OIG published its national referral report. That is the fourth coordinated program-integrity announcement since March, following the executive order, the May 13 letter to all state Attorneys General, and the June and July decertifications. Reading each action alone understates what is happening. Reading them together shows a single, expanding enforcement posture that already covers every state’s fraud unit, not just the two making headlines.
That matters for sequencing. A state whose MFCU looks stable today has no assurance it will look stable at its next recertification date, because the review standard already applies to it. The operational question for a Medicaid MCO is not whether this is happening in “my state” yet. It is whether the plan would know if it started.
One federal-state dispute, six functions that feel it
Compliance
“We referred it” is no longer a closing statement. Programs need a documented answer to what happened after the referral, not just proof it was sent.
SIU / Operations
Referral logs need an outcome field, not just a submission date and recipient, in any state where MFCU capacity is degraded or under review.
Legal / Regulatory Affairs
HHS-OIG’s 53-unit review means any state’s MFCU status can change with little notice. Monitoring needs to be continuous, not tied to renewal cycles.
Government Affairs
State Medicaid agency relationships now carry more weight. Referral protocol clarity is worth raising ahead of the next contract cycle, not after a problem surfaces.
Finance
MFCU funding loss has appeared alongside broader state Medicaid funding scrutiny. That is a materially larger exposure than the fraud unit question alone.
Executive / Board
This is a program-integrity governance question, not just an SIU workflow issue. It belongs on the compliance committee agenda in any state with material Medicaid membership.
Fraud referral compliance needs an owner for the outcome, not just the submission
Referring suspected fraud has always been treated as the finish line of a compliance obligation. HHS-OIG’s own findings, on referral rule variability and on the units now losing certification, argue for treating it as the start of one instead. The table below assigns ownership; the list after it sequences the work.
| Function | Required response | Evidence to retain |
|---|---|---|
| Compliance / Program Integrity | Confirm current HHS-OIG certification status of the MFCU in every state where the plan holds a Medicaid MCO contract; compare the plan’s own state contract’s fraud-referral trigger language, timeframe, and noncompliance provisions against HHS-OIG’s OEI-03-23-00340 findings. | Certification-status check log with date; contract clause excerpts; gap analysis memo. |
| Special Investigations Unit (Operations) | Build or strengthen internal case tracking that records referral submission, recipient, and outcome (or non-response) rather than assuming state or MFCU follow-through. | SIU case log with a referral-to-resolution status field for every submitted referral. |
| Legal / Regulatory Affairs | Monitor HHS-OIG recertification determinations and the broader 53-unit review for every state where the plan operates; assess exposure if a state’s MFCU is decertified or placed under corrective action mid-cycle. | Monitoring log; jurisdictional exposure memo updated as determinations are announced. |
| Government Affairs / State Relations | Engage state Medicaid agency contacts on referral protocol clarity and consequence provisions ahead of contract renewal cycles, particularly in states named in HHS-OIG or CMS program-integrity actions. | Meeting notes; proposed contract redlines; correspondence log. |
| Finance | Model financial exposure from unresolved provider fraud in states where MFCU capacity is degraded, and track whether broader state Medicaid funding actions are underway in the same states. | Fraud-loss estimate by state; reserve review notes; cash-flow contingency memo where applicable. |
Within 7 days
Identify every state where the plan holds a Medicaid MCO contract and check current MFCU certification status against HHS-OIG’s published determinations. Flag any state under active review or already decertified.
Within 30 days
Pull the plan’s own state Medicaid contract’s fraud-referral clause and compare its trigger language, timeframe, and noncompliance provisions against HHS-OIG’s OEI-03-23-00340 findings. Identify gaps and brief compliance leadership.
Within 60–90 days
Build or strengthen an internal SIU mechanism that tracks referral outcomes independent of state or MFCU confirmation, and brief the compliance committee on residual fraud exposure in any state with a decertified or funding-suspended MFCU. These are editorial recommendations, not confirmed CMS or HHS-OIG requirements.
A Medicaid Fraud Control Unit is not a first-tier, downstream, or related entity in the formal CMS sense. A plan does not select it, contract with it, or hold audit rights over it. But functionally, from inside a compliance program, it plays the role of a mandatory receiving party for a control the plan cannot perform itself: investigation and prosecution of suspected fraud. Most compliance programs have built mature oversight frameworks for the delegates they do choose. Pharmacy benefit managers, utilization management vendors, and delegated claims administrators all come with monitoring cadence, documentation standards, and escalation paths. Almost none have an equivalent framework for the involuntary hand-off to a state MFCU.
PCOOB Weekly’s assessment is that HHS-OIG’s July 21 report documents this gap at a national scale, even though the report itself is framed around state oversight of MCOs, not MCO oversight of the referral pipeline. The finding that some states offer MCOs no feedback on referral outcomes has a mirror image on the plan’s side: some plans have no way of knowing whether their compliance obligation actually produced an investigation. That gap was tolerable when MFCU capacity was a reasonable assumption. It is a live compliance question now that federal decertification has moved from a rare event to an active enforcement tool, applied twice in two months against a review standard that now sits over all 53 units.
This is an operational inference based on the pattern of two decertifications and a 53-unit review notice. It is not a claim that any specific state’s MFCU will be decertified next, and not a claim that HHS-OIG has formally redefined MCO referral obligations. What has changed is the cost of not knowing the answer to the follow-up question.
Questions payer leaders should ask
- 01Do we know the current federal certification status of the Medicaid Fraud Control Unit in every state where we operate a Medicaid MCO?
- 02Does our state Medicaid contract define “potential fraud” broadly enough to match what our SIU actually reports, or does it use a narrower “credible allegations” standard?
- 03What is our contractual referral timeframe in each state, and can our SIU consistently meet it?
- 04What happens inside our organization after we submit a fraud referral? Do we track whether the state or MFCU acted on it?
- 05If our state’s MFCU were placed under review or decertified tomorrow, would our compliance program have any way to know, or an alternative escalation path?
- 06Does our compliance committee currently receive reporting on fraud-referral outcomes, or only on referral volume?
- 07Are we treating fraud referral as a documentation obligation, or as a monitored, outcome-tracked control?
Sources
- HHS-OIG: Statement on Federal Decertification of the New York Medicaid Fraud Control Unit
- U.S. Department of Justice, U.S. Attorney’s Office, Northern District of New York: Statement on Federal Decertification of the New York Medicaid Fraud Control Unit
- HHS-OIG: States Have Missed Some Opportunities to Improve Medicaid Managed Care Organizations’ Provider Fraud Referrals (OEI-03-23-00340)
- Fierce Healthcare: OIG: States can improve enforcement of Medicaid MCOs’ fraud referrals
- Fierce Healthcare: Trump administration withholds funds from New York’s Medicaid fraud unit
- KFF: What to Know About Recent Federal Actions Involving State Medicaid Program Integrity
- Modern Healthcare: HHS decertifies Hawaii’s Medicaid Fraud Control Unit
- HHS-OIG: Medicaid Fraud Control Units program overview
About PCOOB Weekly: PCOOB Weekly is an independent digital publication focused on U.S. healthcare payer compliance, operations, governance, oversight, and technology. It provides source-led analysis for Medicare, Medicaid, Commercial, and pharmacy benefit stakeholders.
Until next week, stay briefed.
Frequently asked questions
What is a Medicaid Fraud Control Unit?
A Medicaid Fraud Control Unit (MFCU) is a state-based law enforcement entity, typically housed in a state Attorney General’s office and required to operate independently from the state Medicaid agency, that investigates and prosecutes Medicaid provider fraud and patient abuse or neglect in Medicaid-funded facilities. States that have operated an MFCU for more than 12 quarters receive 75 percent federal matching funds from HHS-OIG, which recertifies each unit annually against performance standards.
Why did HHS-OIG decertify New York’s Medicaid Fraud Control Unit?
HHS-OIG denied recertification effective July 1, 2026, citing persistently low criminal enforcement output, about eight to nine indictments a year against a $60 million annual budget and a staff of more than 270, along with slow case progression, an investigation backlog, and referral and tracking deficiencies, according to HHS-OIG and the U.S. Attorney’s Office for the Northern District of New York. New York’s Attorney General has disputed this characterization.
Does this affect Medicaid managed care organizations directly?
Yes. MCOs are contractually required to refer suspected provider fraud to their state and, in most states, to the MFCU. A separate HHS-OIG evaluation published July 21, 2026 found that referral requirements, timeframes, and enforcement consequences for MCOs vary widely by state, and that some states give MCOs no feedback on what happens to a referral after it is submitted.
Is New York the only state affected?
No. HHS-OIG decertified Hawaii’s MFCU in June 2026, the first action under a nationwide review announced in a May 13, 2026 letter to all 53 state and territory Attorneys General. HHS-OIG has stated it will apply the same rigid compliance review to every unit as recertification dates come due.
What should a Medicaid MCO’s compliance program do now?
Confirm the certification status of the MFCU in every state where it operates, compare its own state contract’s fraud-referral language against HHS-OIG’s July 21 findings on referral variability, and build internal tracking of referral outcomes rather than relying solely on the state or MFCU to close the loop.