Medicaid Managed Care  ·  Signal watch / Operational fault line  · 

The Fraud Unit Got Defunded. The Referral Duty Didn’t.

HHS-OIG has decertified two state Medicaid Fraud Control Unit since June and put all fifty-three units on notice, the same week its own national review found that fraud-referral requirements for managed care organizations vary by design from state to state. Submitting a fraud referral and knowing what happens to it are no longer the same compliance question.

01

Two fraud units lost federal certification in two months. Fifty-one more sit under the same review standard.

In March 2026, an executive order created the Task Force to Eliminate Fraud, chaired by Vice President JD Vance. On May 13, HHS Inspector General March Bell told every state Attorney General to expect “rigid MFCU compliance” review. Hawaii’s Medicaid Fraud Control Unit lost certification in June. New York’s followed on July 1, 2026, funding suspended, corrective actions required.

“Noncompliance with your MFCU obligations can take your State’s entire Medicaid program out of compliance.” (HHS-OIG letter to state Attorneys General, May 13, 2026)
By the numbers
53
state and territory Medicaid Fraud Control Units, all reviewed against the same “rigid compliance” standard
2 MFCUs decertified since June 2026 $1B+ withheld from CA/MN the same week 1–270 days: referral timeframe range across states
Decertified

New York’s Medicaid Fraud Control Unit: the specific numbers behind the decertification

$60M
annual federal funding, now suspended
270+
MFCU staff
8–9
criminal indictments per year, FY2023 and FY2025
4 of 2,000+
annual patient-abuse referrals that produced a conviction

HHS-OIG cited slow case progression, an investigation backlog, and referral and tracking deficiencies. New York’s Attorney General has disputed the characterization. Hawaii’s MFCU, decertified in June, recorded no criminal indictments or convictions for Medicaid fraud from 2022 through 2025; the state responded by creating an independent Medicaid Fraud Strike Force.

What OIG found, nationally

The same week New York lost its unit, OIG reported the referral system itself is unevenly built

Report OEI-03-23-00340, issued July 16 and posted July 21, 2026, evaluated how all states require Medicaid MCOs to refer suspected fraud.

  • Recommendation 1Require all MCOs to refer potential fraud promptly. CMS concurred.
  • Recommendation 2Require state contracts to specify consequences for MCO noncompliance. CMS concurred.
  • Recommendation 3Expand feedback to MCOs on referral outcomes. CMS did not formally concur or nonconcur, but said it has taken steps.
  • Recommendation 4Assess federal-level actions to improve referral volume. CMS did not formally concur or nonconcur, but said it has taken steps.
Reading the pattern

Four months from executive order to a 53-unit review is not a coincidence of timing

Trade press noted that HHS and CMS announced more than $1 billion in additional Medicaid funding withheld from California and Minnesota on the same day OIG published its national referral report. That is the fourth coordinated program-integrity announcement since March, following the executive order, the May 13 letter to all state Attorneys General, and the June and July decertifications. Reading each action alone understates what is happening. Reading them together shows a single, expanding enforcement posture that already covers every state’s fraud unit, not just the two making headlines.

That matters for sequencing. A state whose MFCU looks stable today has no assurance it will look stable at its next recertification date, because the review standard already applies to it. The operational question for a Medicaid MCO is not whether this is happening in “my state” yet. It is whether the plan would know if it started.

Why it matters, by function

One federal-state dispute, six functions that feel it

Compliance

“We referred it” is no longer a closing statement. Programs need a documented answer to what happened after the referral, not just proof it was sent.

SIU / Operations

Referral logs need an outcome field, not just a submission date and recipient, in any state where MFCU capacity is degraded or under review.

Legal / Regulatory Affairs

HHS-OIG’s 53-unit review means any state’s MFCU status can change with little notice. Monitoring needs to be continuous, not tied to renewal cycles.

Government Affairs

State Medicaid agency relationships now carry more weight. Referral protocol clarity is worth raising ahead of the next contract cycle, not after a problem surfaces.

Finance

MFCU funding loss has appeared alongside broader state Medicaid funding scrutiny. That is a materially larger exposure than the fraud unit question alone.

Executive / Board

This is a program-integrity governance question, not just an SIU workflow issue. It belongs on the compliance committee agenda in any state with material Medicaid membership.

Who owns it, what to do

Fraud referral compliance needs an owner for the outcome, not just the submission

Referring suspected fraud has always been treated as the finish line of a compliance obligation. HHS-OIG’s own findings, on referral rule variability and on the units now losing certification, argue for treating it as the start of one instead. The table below assigns ownership; the list after it sequences the work.

FunctionRequired responseEvidence to retain
Compliance / Program IntegrityConfirm current HHS-OIG certification status of the MFCU in every state where the plan holds a Medicaid MCO contract; compare the plan’s own state contract’s fraud-referral trigger language, timeframe, and noncompliance provisions against HHS-OIG’s OEI-03-23-00340 findings.Certification-status check log with date; contract clause excerpts; gap analysis memo.
Special Investigations Unit (Operations)Build or strengthen internal case tracking that records referral submission, recipient, and outcome (or non-response) rather than assuming state or MFCU follow-through.SIU case log with a referral-to-resolution status field for every submitted referral.
Legal / Regulatory AffairsMonitor HHS-OIG recertification determinations and the broader 53-unit review for every state where the plan operates; assess exposure if a state’s MFCU is decertified or placed under corrective action mid-cycle.Monitoring log; jurisdictional exposure memo updated as determinations are announced.
Government Affairs / State RelationsEngage state Medicaid agency contacts on referral protocol clarity and consequence provisions ahead of contract renewal cycles, particularly in states named in HHS-OIG or CMS program-integrity actions.Meeting notes; proposed contract redlines; correspondence log.
FinanceModel financial exposure from unresolved provider fraud in states where MFCU capacity is degraded, and track whether broader state Medicaid funding actions are underway in the same states.Fraud-loss estimate by state; reserve review notes; cash-flow contingency memo where applicable.

Within 7 days

Identify every state where the plan holds a Medicaid MCO contract and check current MFCU certification status against HHS-OIG’s published determinations. Flag any state under active review or already decertified.

Within 30 days

Pull the plan’s own state Medicaid contract’s fraud-referral clause and compare its trigger language, timeframe, and noncompliance provisions against HHS-OIG’s OEI-03-23-00340 findings. Identify gaps and brief compliance leadership.

Within 60–90 days

Build or strengthen an internal SIU mechanism that tracks referral outcomes independent of state or MFCU confirmation, and brief the compliance committee on residual fraud exposure in any state with a decertified or funding-suspended MFCU. These are editorial recommendations, not confirmed CMS or HHS-OIG requirements.

PCOOB Weekly analysis

A Medicaid Fraud Control Unit is not a first-tier, downstream, or related entity in the formal CMS sense. A plan does not select it, contract with it, or hold audit rights over it. But functionally, from inside a compliance program, it plays the role of a mandatory receiving party for a control the plan cannot perform itself: investigation and prosecution of suspected fraud. Most compliance programs have built mature oversight frameworks for the delegates they do choose. Pharmacy benefit managers, utilization management vendors, and delegated claims administrators all come with monitoring cadence, documentation standards, and escalation paths. Almost none have an equivalent framework for the involuntary hand-off to a state MFCU.

PCOOB Weekly’s assessment is that HHS-OIG’s July 21 report documents this gap at a national scale, even though the report itself is framed around state oversight of MCOs, not MCO oversight of the referral pipeline. The finding that some states offer MCOs no feedback on referral outcomes has a mirror image on the plan’s side: some plans have no way of knowing whether their compliance obligation actually produced an investigation. That gap was tolerable when MFCU capacity was a reasonable assumption. It is a live compliance question now that federal decertification has moved from a rare event to an active enforcement tool, applied twice in two months against a review standard that now sits over all 53 units.

This is an operational inference based on the pattern of two decertifications and a 53-unit review notice. It is not a claim that any specific state’s MFCU will be decertified next, and not a claim that HHS-OIG has formally redefined MCO referral obligations. What has changed is the cost of not knowing the answer to the follow-up question.

Questions & sources

Questions payer leaders should ask

  • 01Do we know the current federal certification status of the Medicaid Fraud Control Unit in every state where we operate a Medicaid MCO?
  • 02Does our state Medicaid contract define “potential fraud” broadly enough to match what our SIU actually reports, or does it use a narrower “credible allegations” standard?
  • 03What is our contractual referral timeframe in each state, and can our SIU consistently meet it?
  • 04What happens inside our organization after we submit a fraud referral? Do we track whether the state or MFCU acted on it?
  • 05If our state’s MFCU were placed under review or decertified tomorrow, would our compliance program have any way to know, or an alternative escalation path?
  • 06Does our compliance committee currently receive reporting on fraud-referral outcomes, or only on referral volume?
  • 07Are we treating fraud referral as a documentation obligation, or as a monitored, outcome-tracked control?

Sources

About PCOOB Weekly: PCOOB Weekly is an independent digital publication focused on U.S. healthcare payer compliance, operations, governance, oversight, and technology. It provides source-led analysis for Medicare, Medicaid, Commercial, and pharmacy benefit stakeholders.

Until next week, stay briefed.

FAQ

Frequently asked questions

What is a Medicaid Fraud Control Unit?

A Medicaid Fraud Control Unit (MFCU) is a state-based law enforcement entity, typically housed in a state Attorney General’s office and required to operate independently from the state Medicaid agency, that investigates and prosecutes Medicaid provider fraud and patient abuse or neglect in Medicaid-funded facilities. States that have operated an MFCU for more than 12 quarters receive 75 percent federal matching funds from HHS-OIG, which recertifies each unit annually against performance standards.

Why did HHS-OIG decertify New York’s Medicaid Fraud Control Unit?

HHS-OIG denied recertification effective July 1, 2026, citing persistently low criminal enforcement output, about eight to nine indictments a year against a $60 million annual budget and a staff of more than 270, along with slow case progression, an investigation backlog, and referral and tracking deficiencies, according to HHS-OIG and the U.S. Attorney’s Office for the Northern District of New York. New York’s Attorney General has disputed this characterization.

Does this affect Medicaid managed care organizations directly?

Yes. MCOs are contractually required to refer suspected provider fraud to their state and, in most states, to the MFCU. A separate HHS-OIG evaluation published July 21, 2026 found that referral requirements, timeframes, and enforcement consequences for MCOs vary widely by state, and that some states give MCOs no feedback on what happens to a referral after it is submitted.

Is New York the only state affected?

No. HHS-OIG decertified Hawaii’s MFCU in June 2026, the first action under a nationwide review announced in a May 13, 2026 letter to all 53 state and territory Attorneys General. HHS-OIG has stated it will apply the same rigid compliance review to every unit as recertification dates come due.

What should a Medicaid MCO’s compliance program do now?

Confirm the certification status of the MFCU in every state where it operates, compare its own state contract’s fraud-referral language against HHS-OIG’s July 21 findings on referral variability, and build internal tracking of referral outcomes rather than relying solely on the state or MFCU to close the loop.

ABOUT THE AUTHOR
Namrata Giri
PCOOB Weekly is an independent LinkedIn newsletter covering payer compliance, operations, oversight, risk, governance, audit, reporting, data, AI, and finance for U.S. health plan leaders.
Connect on LinkedIn

Discover more from PCOOB Weekly

Subscribe now to keep reading and get access to the full archive.

Continue reading