PCOOB Weekly  •  June 23, 2026  •  Regulatory Analysis

The Directory Is Wrong. Twice.

Medicaid managed care plans submit network data to state regulators and publish separate directories for enrollees. New OIG companion reports find both are substantially inaccurate, and the reason is structural, not incidental.

02

The oversight mechanism that runs on wrong data

The Medicaid managed care regulatory framework puts states in charge of ensuring their contracted plans maintain adequate provider networks. Under 42 CFR 438.68, states must establish and enforce network adequacy standards. The mechanism they use is straightforward: plans submit network lists, and states review those lists to assess whether enough providers are available in key categories.

Two companion OIG evaluations published June 11 and released June 16, 2026 tested that mechanism against the plans operated by Centene, Elevance, and UnitedHealthcare in five states. These three organizations collectively cover more than 29 million Medicaid enrollees across 38 of the 42 states with comprehensive managed care programs. They are not a subset of the market. They are the market.

The first evaluation (OEI-05-24-00091) examined the network lists that plans submitted to state regulators for maternal health oversight. About one-quarter of the maternal health providers on those lists reported to OIG that they were not actually in-network with the plan. More than one-quarter of listed providers had no accurate phone number. And nearly half of the providers on the state-facing network lists did not appear at all in the plans’ own public-facing online directories.

The second evaluation (OEI-05-24-00090) examined those online directories — the consumer-facing tools enrollees use when they need to find an in-network provider. The two reports are designed to be read together: the regulatory submission and the consumer-facing output of the same plan’s network data are both wrong, in different ways, simultaneously.

The context matters. Medicaid pays for more than 40 percent of all births in the United States. Most pregnant Medicaid enrollees are covered through managed care plans. The United States already records maternal mortality rates worse than every comparable high-income country. When the regulatory network list is wrong and the enrollee directory is also wrong, the failure is not administrative. It is clinical.

Access the full report

Plans operating two separate data environments
All three
Centene, Elevance, UnitedHealthcare, across five states
Required reconciliation between regulatory and member data
None
No federal requirement that the two systems agree at the point of submission
Enrollees covered by these three organizations’ Medicaid plans
29M+
In 38 of 42 states with comprehensive managed care programs as of 2025

Here are five numbers from the reports

Out of network providers

At 35%, Centene had the largest share of maternal health providers on the network list who were actually out of network, versus 19% at UnitedHealthcare and 18% at Elevance.

Inaccurate provider details

Overall, one-third of providers in the directories who reported being in network also documented at least one inaccurate phone number or address for themselves.

Location discrepancies

Twenty-one percent of in-network maternal health providers in provider directories said they did not currently work from at least one of the listed locations.

Online-offline mismatch provider

Of the providers who reported not being in network, 77% were not listed in the online provider directories, indicating online provider directories were more representative for this group than network lists sent to states.

Looking across the plans, 22% of providers reported as in network were not listed in their respective plan’s online provider directory. For Centene, 55% of in-network providers from the network list were not in the provider directory, followed by 44% for UnitedHealthcare and 39% for Elevance.

“The oversight mechanism and the member access mechanism have both failed — silently, at scale.”
PCOOB Weekly analysis, June 23, 2026
Providers on state network lists absent from enrollee-facing online directories
~50%
Of the maternal health providers that Centene, Elevance, and UnitedHealthcare submitted on state regulatory network lists, nearly half did not appear in the plans’ own public-facing online directories.
Source: OIG OEI-05-24-00091, issued June 11, 2026
DATA GAP
Three findings. One plan. Two failed data layers.
~25%
Of maternal health providers on state-facing network lists reported to OIG they were not actually in-network with the plan
>25%
Of providers on state network lists had no accurate phone number on file, making them unreachable by enrollees even if found
~50%
Of providers on state regulatory network lists did not appear in the plans’ own public-facing online directories

These findings span the plans operated by Centene, Elevance, and UnitedHealthcare, three organizations whose Medicaid managed care plans collectively cover more than 29 million enrollees. The evaluation methodology was direct: OIG selected providers from the network lists plans submitted to states for regulatory review, then checked whether those same providers appeared in the plans’ online directories and whether the contact information was accurate.

The scope matters because Medicaid pays for more than 40 percent of all births in the United States, and most pregnant Medicaid enrollees receive care through managed care plans. The United States already records maternal mortality rates worse than those of any comparable high-income country. Provider directory accuracy in this population is not an administrative formality. It is an access infrastructure question.

This is not a maintenance problem. It is a governance architecture problem.

The instinctive framing for provider directory inaccuracies is that plans have update backlogs. Provider contracts change frequently. Systems don’t always reflect current status. That framing, while not wrong, is incomplete — and accepting it leads to the wrong intervention.

The more precise finding in these OIG evaluations is that managed care organizations operate two separate data environments for provider network information: one for state regulatory compliance, and one for member navigation. These environments are produced by different teams, built on different systems, and updated on different schedules. There is no federal requirement under the current Medicaid managed care regulatory framework that the two must agree at the point of state submission or at the point of member use.

That is what the nearly 50 percent discrepancy between state network lists and online directories reflects. It is not a question of which list is more current. It is that the provider contracting workflow, the regulatory reporting extract, and the member-facing portal draw from databases that are not integrated and are not required to reconcile.

This is a data governance architecture problem. Plans built the compliance function and the member services function as separate operational domains. The data that flows into state network adequacy review and the data that flows into the member-facing directory were never integrated at the source. They diverge because they were designed to diverge. The practical consequence is that a state reviewing network adequacy may be evaluating a plan’s compliance based on a provider set that is materially different from the network the plan’s own system shows to members. Both outputs are generated by the same organization. Neither reflects the actual contracted network with accuracy.

For compliance teams

State network adequacy certification runs on self-reported data. If that data has a material inaccuracy rate, every certification downstream is built on a flawed input. The regulatory review produces false assurance — and the liability is already in the filed submission.

For IT and data teams

This is a data architecture problem, not a data quality problem. Provider contracting, credentialing, and directory management are separate departmental functions with separate databases. No shared source of truth. No automated reconciliation. No single update that propagates to both outputs.

The structural gap

Most state contracts set submission frequencies for network lists. They do not require that the state-facing data and the enrollee-facing directory match at the time of submission. The governance framework assumed integration that does not exist in most managed care operations.

What this means for how plans get held accountable

CMS concurred with both OIG recommendations: to work with states to improve the accuracy of provider data used in network adequacy evaluation, and to hold managed care plans accountable for the accuracy of both their state-facing network lists and their member-facing online directories. Under 42 CFR 438.68, states must establish and enforce network adequacy standards for Medicaid managed care plans. The mechanism they use is largely built on self-reported data: plans submit network lists, states review those lists, and enrollees are presumed to be adequately covered. When the list is wrong at the source, every step downstream is unreliable.

That concurrence matters. In several recent OIG evaluations related to Medicare Advantage risk adjustment, CMS declined to specify concurrence or nonconcurrence with recommendations, leaving the accountability gap open. Here, CMS agreed. That is a signal of the direction of oversight, even if the enforcement mechanisms have not yet been formalized.

The state contract authority to act on network adequacy deficiencies is not future risk. States can impose financial penalties, suspend enrollment, and terminate managed care contracts when network adequacy standards are not met. Those standards are assessed using the data plans submit. When that data has a material inaccuracy rate, the liability is already present. It just hasn’t been fully measured yet.

The governance question is direct: who in the organization is responsible for certifying that the network list submitted to the state and the online directory shown to enrollees are drawing from the same source, and reconciled before submission?

June 11, 2026
OIG issues two companion evaluations (OEI-05-24-00090 and OEI-05-24-00091) on Medicaid managed care provider directory accuracy for maternal health
June 16, 2026
Both reports posted publicly at OIG.HHS.GOV. CMS concurs with all three OIG recommendations across the two reports.
June 2026 (ongoing)
New MCPAR reporting requirements take effect. States now receive plan-level prior authorization data, adding another data layer to the oversight environment.
Ongoing
State authority to impose penalties, suspend enrollment, and terminate contracts for network adequacy failures remains active. Accountability depends on data accuracy.
08

What leaders should recognize, and act on

The question this raises for compliance, operations, and IT leaders is not whether their plans have a provider directory. Every plan has one. The question is whether the data environment that generates the regulatory network list and the data environment that populates the enrollee-facing directory share a common source, update in sync, and are reconciled against each other on a defined schedule, and whether anyone is formally responsible for that reconciliation.

Most Medicaid managed care organizations have not been required to demonstrate formally that the two systems agree. The OIG’s findings suggest that, at scale, they don’t. The risk for plans is not confined to future enforcement action. States already hold the authority, through managed care contracts and 42 CFR 438, to impose financial penalties, suspend enrollment, and terminate contracts when network adequacy requirements are not met. That authority runs on the accuracy of the data plans submit. These evaluations show that data is wrong.

CMS concurred with all OIG recommendations. The signal is directional: standards for provider directory accuracy are moving toward greater accountability, and the current gap between regulatory data and consumer-facing data is now a matter of formal federal record.

The compounding layer: new MCPAR requirements

Effective this month, states are required to collect new plan-level prior authorization data through the Managed Care Program Annual Report (MCPAR). This includes total PA request volumes, denial and approval rates, and average decision times by plan.

As states receive more granular plan-level data across multiple performance dimensions, the capacity to identify discrepancies between what plans report and what actually exists increases. Organizations that have not invested in aligning their regulatory reporting and member-facing data environments are accumulating a compounding exposure: each new reporting layer creates another potential point of divergence between the plan’s self-reported picture and the state’s growing ability to test it.

The MCOs named in this evaluation cover the majority of the Medicaid managed care market. If the data architecture problem described in the OIG’s findings is systemic across large MCOs — which the scope of these evaluations strongly suggests, then the accountability reckoning, when it comes, will not be plan-specific. It will be structural.

Organizations that have not invested in aligning their regulatory reporting and member-facing data environments are taking on compounding compliance risk as each new reporting requirement adds another point of possible divergence.

Why this matters across functions

The provider directory inaccuracy finding is a cross-functional governance problem. Here is where it lands.

Compliance

State network adequacy certification is based on self-reported network lists. A ~25% provider inaccuracy rate means the certification is built on data that does not reflect the actual available network. The liability is already in the submitted filing.

Operations

Regulatory reporting and member directory management are separate workflows with separate update schedules. The operational design produces divergence. Resolving it requires workflow integration, not just data cleanup.

IT / Data governance

Provider contracting, credentialing, and directory management live in separate systems. There is no shared source of truth and no automated reconciliation between the regulatory extract and the member-facing portal. This is an architecture problem.

Risk and audit

CMS concurred with all three OIG recommendations. The trajectory is toward stronger accountability standards. State contract authority to sanction plans for network adequacy deficiencies is already active, and runs on data these evaluations show is wrong.

Member experience

An enrollee searching the online directory for an in-network OB-GYN is navigating a dataset that may be different from the one the state used to certify coverage. For Medicaid maternal health — where outcomes are already poor, this is a direct clinical access barrier.

State relations

The new MCPAR PA data requirement adds another reporting layer starting this month. As state regulators receive more plan-level data, the exposure surface for discrepancies between reported and actual network status expands further.

Questions leaders should ask now

01
Does your plan’s provider contracting system, regulatory network list extract, and online directory portal draw from a single shared source of truth, or from separate databases updated on different schedules?
02
Is there a documented reconciliation process that verifies the state-facing network list and the enrollee-facing online directory agree before the network list is submitted to the state?
03
Who in your organization is formally responsible for certifying the accuracy of the network list submitted to the state, and have they reviewed it against the current enrollee-facing directory within the last submission cycle?
04
For Medicaid managed care plans specifically, when was your last provider-level outreach confirming in-network participation, not a system record pull, but actual provider confirmation?
05
Has your organization modeled the network adequacy liability exposure if your reported network list is found to have a material inaccuracy rate under state contract terms and applicable penalties?
06
How will the reconciliation between state network lists and consumer directories be managed as the new MCPAR prior authorization data requirements create additional plan-level reporting obligations this month?
07
If CMS issues implementation guidance following its concurrence with the OIG recommendations, what operational changes would be required, and is your organization positioned to respond within a reasonable compliance window?
08
For plans with FDR relationships covering provider directory management or member navigation functions, who is accountable for the accuracy of the data those FDRs maintain on behalf of the plan?
Namrata Giri

PCOOB Weekly is an independent newsletter covering U.S. healthcare payer compliance, operations, governance, and regulatory intelligence. Published weekly for health plan executives, compliance leaders, and operations professionals.

Until next week, stay briefed.
Follow on LinkedIn

Subscribe