The Directory Is Wrong. Twice.
Medicaid managed care plans submit network data to state regulators and publish separate directories for enrollees. New OIG companion reports find both are substantially inaccurate, and the reason is structural, not incidental.
In this edition
- The oversight mechanism that runs on wrong data
- Here are five numbers from the reports
- Providers on state network lists
- Three findings. One plan. Two failed data layers.
- Root cause analysis
- What this means for how plans get held accountable
- What leaders should recognize, and act on
- Why this matters across functions
- Questions for leaders and sources
The oversight mechanism that runs on wrong data
The Medicaid managed care regulatory framework puts states in charge of ensuring their contracted plans maintain adequate provider networks. Under 42 CFR 438.68, states must establish and enforce network adequacy standards. The mechanism they use is straightforward: plans submit network lists, and states review those lists to assess whether enough providers are available in key categories.
Two companion OIG evaluations published June 11 and released June 16, 2026 tested that mechanism against the plans operated by Centene, Elevance, and UnitedHealthcare in five states. These three organizations collectively cover more than 29 million Medicaid enrollees across 38 of the 42 states with comprehensive managed care programs. They are not a subset of the market. They are the market.
The first evaluation (OEI-05-24-00091) examined the network lists that plans submitted to state regulators for maternal health oversight. About one-quarter of the maternal health providers on those lists reported to OIG that they were not actually in-network with the plan. More than one-quarter of listed providers had no accurate phone number. And nearly half of the providers on the state-facing network lists did not appear at all in the plans’ own public-facing online directories.
The second evaluation (OEI-05-24-00090) examined those online directories — the consumer-facing tools enrollees use when they need to find an in-network provider. The two reports are designed to be read together: the regulatory submission and the consumer-facing output of the same plan’s network data are both wrong, in different ways, simultaneously.
The context matters. Medicaid pays for more than 40 percent of all births in the United States. Most pregnant Medicaid enrollees are covered through managed care plans. The United States already records maternal mortality rates worse than every comparable high-income country. When the regulatory network list is wrong and the enrollee directory is also wrong, the failure is not administrative. It is clinical.
Here are five numbers from the reports
Out of network providers
At 35%, Centene had the largest share of maternal health providers on the network list who were actually out of network, versus 19% at UnitedHealthcare and 18% at Elevance.
Inaccurate provider details
Overall, one-third of providers in the directories who reported being in network also documented at least one inaccurate phone number or address for themselves.
Location discrepancies
Twenty-one percent of in-network maternal health providers in provider directories said they did not currently work from at least one of the listed locations.
Online-offline mismatch provider
Of the providers who reported not being in network, 77% were not listed in the online provider directories, indicating online provider directories were more representative for this group than network lists sent to states.
Looking across the plans, 22% of providers reported as in network were not listed in their respective plan’s online provider directory. For Centene, 55% of in-network providers from the network list were not in the provider directory, followed by 44% for UnitedHealthcare and 39% for Elevance.
“The oversight mechanism and the member access mechanism have both failed — silently, at scale.”
PCOOB Weekly analysis, June 23, 2026
These findings span the plans operated by Centene, Elevance, and UnitedHealthcare, three organizations whose Medicaid managed care plans collectively cover more than 29 million enrollees. The evaluation methodology was direct: OIG selected providers from the network lists plans submitted to states for regulatory review, then checked whether those same providers appeared in the plans’ online directories and whether the contact information was accurate.
The scope matters because Medicaid pays for more than 40 percent of all births in the United States, and most pregnant Medicaid enrollees receive care through managed care plans. The United States already records maternal mortality rates worse than those of any comparable high-income country. Provider directory accuracy in this population is not an administrative formality. It is an access infrastructure question.
This is not a maintenance problem. It is a governance architecture problem.
The instinctive framing for provider directory inaccuracies is that plans have update backlogs. Provider contracts change frequently. Systems don’t always reflect current status. That framing, while not wrong, is incomplete — and accepting it leads to the wrong intervention.
The more precise finding in these OIG evaluations is that managed care organizations operate two separate data environments for provider network information: one for state regulatory compliance, and one for member navigation. These environments are produced by different teams, built on different systems, and updated on different schedules. There is no federal requirement under the current Medicaid managed care regulatory framework that the two must agree at the point of state submission or at the point of member use.
That is what the nearly 50 percent discrepancy between state network lists and online directories reflects. It is not a question of which list is more current. It is that the provider contracting workflow, the regulatory reporting extract, and the member-facing portal draw from databases that are not integrated and are not required to reconcile.
This is a data governance architecture problem. Plans built the compliance function and the member services function as separate operational domains. The data that flows into state network adequacy review and the data that flows into the member-facing directory were never integrated at the source. They diverge because they were designed to diverge. The practical consequence is that a state reviewing network adequacy may be evaluating a plan’s compliance based on a provider set that is materially different from the network the plan’s own system shows to members. Both outputs are generated by the same organization. Neither reflects the actual contracted network with accuracy.
State network adequacy certification runs on self-reported data. If that data has a material inaccuracy rate, every certification downstream is built on a flawed input. The regulatory review produces false assurance — and the liability is already in the filed submission.
This is a data architecture problem, not a data quality problem. Provider contracting, credentialing, and directory management are separate departmental functions with separate databases. No shared source of truth. No automated reconciliation. No single update that propagates to both outputs.
Most state contracts set submission frequencies for network lists. They do not require that the state-facing data and the enrollee-facing directory match at the time of submission. The governance framework assumed integration that does not exist in most managed care operations.
What this means for how plans get held accountable
CMS concurred with both OIG recommendations: to work with states to improve the accuracy of provider data used in network adequacy evaluation, and to hold managed care plans accountable for the accuracy of both their state-facing network lists and their member-facing online directories. Under 42 CFR 438.68, states must establish and enforce network adequacy standards for Medicaid managed care plans. The mechanism they use is largely built on self-reported data: plans submit network lists, states review those lists, and enrollees are presumed to be adequately covered. When the list is wrong at the source, every step downstream is unreliable.
That concurrence matters. In several recent OIG evaluations related to Medicare Advantage risk adjustment, CMS declined to specify concurrence or nonconcurrence with recommendations, leaving the accountability gap open. Here, CMS agreed. That is a signal of the direction of oversight, even if the enforcement mechanisms have not yet been formalized.
The state contract authority to act on network adequacy deficiencies is not future risk. States can impose financial penalties, suspend enrollment, and terminate managed care contracts when network adequacy standards are not met. Those standards are assessed using the data plans submit. When that data has a material inaccuracy rate, the liability is already present. It just hasn’t been fully measured yet.
The governance question is direct: who in the organization is responsible for certifying that the network list submitted to the state and the online directory shown to enrollees are drawing from the same source, and reconciled before submission?
What leaders should recognize, and act on
The question this raises for compliance, operations, and IT leaders is not whether their plans have a provider directory. Every plan has one. The question is whether the data environment that generates the regulatory network list and the data environment that populates the enrollee-facing directory share a common source, update in sync, and are reconciled against each other on a defined schedule, and whether anyone is formally responsible for that reconciliation.
Most Medicaid managed care organizations have not been required to demonstrate formally that the two systems agree. The OIG’s findings suggest that, at scale, they don’t. The risk for plans is not confined to future enforcement action. States already hold the authority, through managed care contracts and 42 CFR 438, to impose financial penalties, suspend enrollment, and terminate contracts when network adequacy requirements are not met. That authority runs on the accuracy of the data plans submit. These evaluations show that data is wrong.
CMS concurred with all OIG recommendations. The signal is directional: standards for provider directory accuracy are moving toward greater accountability, and the current gap between regulatory data and consumer-facing data is now a matter of formal federal record.
The compounding layer: new MCPAR requirements
Effective this month, states are required to collect new plan-level prior authorization data through the Managed Care Program Annual Report (MCPAR). This includes total PA request volumes, denial and approval rates, and average decision times by plan.
As states receive more granular plan-level data across multiple performance dimensions, the capacity to identify discrepancies between what plans report and what actually exists increases. Organizations that have not invested in aligning their regulatory reporting and member-facing data environments are accumulating a compounding exposure: each new reporting layer creates another potential point of divergence between the plan’s self-reported picture and the state’s growing ability to test it.
The MCOs named in this evaluation cover the majority of the Medicaid managed care market. If the data architecture problem described in the OIG’s findings is systemic across large MCOs — which the scope of these evaluations strongly suggests, then the accountability reckoning, when it comes, will not be plan-specific. It will be structural.
Organizations that have not invested in aligning their regulatory reporting and member-facing data environments are taking on compounding compliance risk as each new reporting requirement adds another point of possible divergence.
Why this matters across functions
The provider directory inaccuracy finding is a cross-functional governance problem. Here is where it lands.
State network adequacy certification is based on self-reported network lists. A ~25% provider inaccuracy rate means the certification is built on data that does not reflect the actual available network. The liability is already in the submitted filing.
Regulatory reporting and member directory management are separate workflows with separate update schedules. The operational design produces divergence. Resolving it requires workflow integration, not just data cleanup.
Provider contracting, credentialing, and directory management live in separate systems. There is no shared source of truth and no automated reconciliation between the regulatory extract and the member-facing portal. This is an architecture problem.
CMS concurred with all three OIG recommendations. The trajectory is toward stronger accountability standards. State contract authority to sanction plans for network adequacy deficiencies is already active, and runs on data these evaluations show is wrong.
An enrollee searching the online directory for an in-network OB-GYN is navigating a dataset that may be different from the one the state used to certify coverage. For Medicaid maternal health — where outcomes are already poor, this is a direct clinical access barrier.
The new MCPAR PA data requirement adds another reporting layer starting this month. As state regulators receive more plan-level data, the exposure surface for discrepancies between reported and actual network status expands further.
Questions leaders should ask now
Sources
- OIG OEI-05-24-00091: Inaccurate Medicaid Managed Care Network Lists May Compromise State Oversight of Access to Maternal Health Care, OIG, June 11, 2026
- OIG OEI-05-24-00090: Inaccurate Medicaid Managed Care Provider Directories May Limit Enrollees’ Access to Maternal Health Care, OIG, June 11, 2026
- 42 CFR 438.68, Medicaid Managed Care Access, Finance, and Quality Final Rule, Federal Register, May 10, 2024
- Medicaid Managed Care Reporting and Transparency: MCPAR Requirements, KFF
- OIG A-02-23-01020: CMS Potentially Overpaid Medicare Advantage Organizations $462 Million Based on Certain Unsupported Acute Stroke Diagnosis Codes, OIG, May 28, 2026 (referenced for CMS non-concurrence contrast)