RESOURCE CENTER
Audits, CAPs, Sanctions, and Your Encounter Data
Audits don’t start with an auditor. They originate eighteen months earlier in a pended encounter that wasn’t resolved and an 834 reconciliation no one documented. By the time the notice arrives, the record either exists as proof which a plan can provide promptly, and that an auditor can trust. Or it doesn’t. And the compliance runway is shorter than the relevant calendar dates suggest.
California has been scoring every plan’s encounter data quarterly since January 2026 and posts the report cards publicly. But the monetary sanctions tied to that scoring don’t begin until July 1, 2027. In other words, CA plans are being graded, on the record, months before the grades carry a price. In Arizona, sanction letters by plan have been published quarterly for more than fifteen years. From January 1, 2027, the H.R.1 enrollment provisions double redetermination volume through the same data layer that feeds encounters.
State agencies sanction in escalating phases: notice of concern, notice to cure, mandated corrective action plan, then sanction. Each stage offers plans a window to produce the necessary evidence within a deadline. CMS resumed T-MSIS data-quality compliance actions in September 2025. While formal accountability to meet the federal floor rests with the state, the operational pressure lands on the plan, because the plan holds the only copy of the evidence.
This page explores how enforcement actually works, what auditors ask a plan to produce, how ten states differ, and what a plan can do now to ensure audit defensibility or to triage a sanctions challenge already underway.
How Enforcement Works
There’s no single national answer to “what happens if our encounter data is late?” Two federal provisions create the floor. Each state then builds its own machinery on top of these.
The escalation ladder
Arizona writes this down explicitly in its sanctions policy, and MACPAC found the same pattern in its review of 34 states’ managed care program annual reports: agencies reach for corrective action long before they reach for a fine.
Links: Ladder as published in AHCCCS ACOM Policy 408, Sanctions. Escalation pattern across states documented in MACPAC’s June 2026 Report to Congress, Chapter 3.
Public visibility varies
Medicaid managed care enforcement is contractual and state-administered. 42 CFR 438.66(e) only requires the state to report sanctions and corrective actions in an annual report at the end of the contract year, and the Medicaid statute doesn’t require timely public reporting of plan sanctions at all.
Medicare Advantage enforcement is publicly visible because CMS publishes notices when issued. On the Medicaid side, per KFF, enforcement is slower to surface and leans heavily on corrective action plans (CAPs) rather than fines: fewer than a quarter of managed care states reported issuing any monetary or non-monetary penalty for network adequacy noncompliance over a three-year period, excluding CAPs.
Arizona is the conspicuous exception. AHCCCS publishes individual final sanction letters for encounter data noncompliance, quarterly by plan, going back more than fifteen years. These published letters make pended encounters a visible, recurring basis for sanction, and they are not its only basis. AHCCCS also sanctions for data validation failures, accreditation, and administrative cost percentage.
The rest of the country is less visible, which poses a problem for plans relying on the news to estimate their own exposure.
How Plans Are Affected
Plans don’t run the audit, set submission windows, or write the error thresholds. But the plan is the only party that can produce the evidence, and pays when it can’t.
Clean claims and clean encounters are not the same file. A plan can adjudicate correctly, pay providers on time, and still fail an encounter audit because the state isn’t auditing whether you paid the claim. It’s auditing whether the record you sent the state matches the claim you actually paid, in the state’s format, inside the state’s window, per encounter. Most plan architectures were built to handle only part of the puzzle.
Claims automation on untrustworthy data is high risk. Your first move is to find out what your data would say to an auditor, a state reviewer, or a model – before someone else does.
Chris Sawotin, Chief Executive Officer, CureIS Healthcare
How the burden moves
The requirement is written at the top. The evidence only exists in the middle.
What fails
See the enrollment side in full →
Where Things Stand
September 2026
Enforcement in this area moves in lag.
T-MSIS compliance actions resumed a year ago.
T-MSIS data-quality compliance actions resumed September 1, 2025. Under SHO 25-002 the escalation is two steps, not one: miss quality targets for two consecutive months and CMS notifies the state of potential risk; miss two additional consecutive months and CMS sends a letter requesting a corrective action plan within 30 days. File layout version 4 is expected in production by September 30, 2026. The accountability is the state's. The data is yours.
QMED 2.0 is live. Monetary sanctions begin July 2027.
Under APL 26-003, encounters submitted on or after January 1, 2026 are measured quarterly as pass or fail, across completeness, accuracy, reasonability, timeliness and uniqueness. DHCS began posting quarterly report cards publicly no earlier than April 1, 2026. Enforcement specific to QMED 2.0, including its monetary sanctions, starts July 1, 2027 — so plans have roughly one more measurement year on the public record before the scoring itself carries a price. DHCS retains its existing enforcement authority under APL 25-007 in the meantime.
CMS program-integrity deferrals in 2026 targeted state-claimed expenditures, not any plan's encounter file. They still matter here for one reason: when a state has to document what it paid for, it comes asking the plans. The plan holds the only copy of the evidence.
Fact Sheet
Audits, CAPs and sanctions by numbers and dates
Key details, effective dates, state-by-state mechanics, and sources. Every figure below traces to a state contract, administrative rule, agency policy manual, or published audit report.
Sources: AHCCCS Encounter Manual and Annual Data Validation Audit findings; MACPAC June 2026 Report to Congress, Chapter 3 (MCPAR review, performance year 2023, 34 states); 42 CFR 438.602(e).
Key dates
| When | What happens |
|---|---|
| May 28, 2025 | CMS issues a State Health Official letter on T-MSIS data-reporting compliance. |
| Sep 1, 2025 | T-MSIS data-quality compliance actions resume. Per SHO 25-002, escalation runs in two steps: two consecutive months missing quality targets triggers a CMS notice of potential risk, and two additional consecutive months triggers a letter requesting a corrective action plan within 30 days. |
| Jan 1, 2026 | California begins measuring encounter data quality quarterly as pass or fail under QMED 2.0, per APL 26-003. |
| Apr 1, 2026 | Earliest date DHCS begins publicly posting quarterly QMED 2.0 report cards by plan. |
| Jun 2026 | MACPAC's June Report to Congress, Chapter 3, publishes the 34-state accountability review and recommends CMS issue guidance on consistent reporting of sanctions, liquidated damages, and informal interventions. |
| Sep 30, 2026 | T-MSIS file layout version 4 expected in production. |
| Jan 1, 2027 | H.R.1 enrollment provisions land together. Addresses and SSNs collected and furnished to the Secretary (§ 71103). Quarterly Death Master File verification with retroactive reenrollment on erroneous disenrollment (§ 71104). Six-month redeterminations begin for renewals scheduled on or after this date (§ 71107). |
| Jul 1, 2027 | California enforcement specific to QMED 2.0, including monetary sanctions, begins. Consistent with APL 25-007. |
| Jan 1, 2028 | H.R.1 § 71105 provider and supplier Death Master File checks take effect. Not to be confused with the enrollee checks a year earlier. |
| Oct 1, 2029 | The Secretary must establish a centralized enrollment verification system letting states cross-check for multi-state enrollment (§ 71103). |
Ten states, ten different ways to be wrong
Same federal floor. No national encounter data standard underneath it. Every state sets its own submission window, its own error thresholds, its own penalty mechanism, and decides for itself whether any of it becomes public. A plan operating in more than one state is not managing one compliance obligation. It is managing a different one per contract.
| State | The standard that's measured | How the penalty works | Public record |
|---|---|---|---|
| Arizona | Two separate clocks. Encounters must be submitted within 210 days of the end of the month of service or the date of enrollment, whichever is later. Once submitted, all pended encounters must be resolved within 120 calendar days of the processing date — that second clock is the sanction trigger. Separately, an annual data validation audit measuring encounter omission, element omission, element surplus and element accuracy, by professional and facility form type. | Pended-encounter sanctions assessed quarterly on a count basis. Validation studies can produce a sanction, a required CAP, or both; at or below the 5% threshold, no sanction applies. State rule also allows suspension of further member enrollment and a monetary sanction against capitation prepayment. | Letters published quarterly |
| California | Encounters submitted on or after January 1, 2026 measured quarterly as pass or fail under QMED 2.0, across completeness, accuracy, reasonability, timeliness and uniqueness. DHCS materials also reference consistency — check the current methodology document rather than assuming the legacy four. | Public quarterly report cards from April 2026; QMED 2.0 monetary sanctions from July 1, 2027. State law allows up to $25,000 first violation, $50,000 second, $100,000 each subsequent — assessable per day, and per affected beneficiary. | Sanction letters published |
| Texas | 98% of all 835 transactions within 30 days of an accepted 837 encounter carrying an internal control number, including adjustments and voids. Encounters submitted monthly. | Liquidated damages up to $5,000 for a first quarter of claims-processing noncompliance, up to $25,000 per quarter after. Encounter data is on the list of standards for which the state cannot waive damages. Damages are unallowable costs, excluded from the medical loss ratio. | Posted quarterly, with maximums |
| Florida | Statute requires compliance with Medicaid Encounter Data System reporting, HIPAA-compliant electronic format, and agency deadlines. | Three tracked action types: corrective action plans, liquidated damages, and sanctions. The state's framing is that damages are not punitive but estimates of its projected loss. In FY2023–24, 288 final actions produced $33.2 million in liquidated damages across all compliance categories, not encounter-only, and every contracted plan had damages levied against it. One plan's desk review drove most of the single largest total. | Per-plan dashboards |
| Washington | Encounter data submitted at minimum monthly, no later than 30 calendar days from the end of the month the plan paid the liability. Clean claims: 99% within 90 days of receipt. | Contract language is unusually broad — the state may sanction for submitting reports, documents, data or any other information that is inaccurate, incomplete, untruthful or untimely. Failure to meet a CAP's terms opens sanctions, liquidated damages, or any other remedy allowed. | Final audit reports published |
| Oregon | Valid claims submitted within 45 days of adjudication, and encounter data requiring correction fixed within 63 days of notification. Includes encounters where the plan determined liability exists even if it paid nothing. | An administrative performance withhold equal to 1% of the adjusted capitation payment for the subject month, assessed monthly. Distinct from the quality pool withhold. An external review organization has run encounter data validation since 2020, including medical record review against submitted encounters. | EQRO validation reports |
| New Jersey | Encounter denial rate below 2% and duplicate encounter rate below 2%, measured separately, monthly. Required data quality assurance plan covering timely capture, accuracy, completeness, and internal audit procedures. | Withhold then liquidate: failure initially withholds capitation until resolved; if standards still aren't met after a specified period, the withheld amounts are liquidated and not recoverable. Damages are cost-based, set to make the state whole, which is why no fee schedule exists. State rule also permits suspending new enrollment and letting enrollees transfer out without cause. | Monthly reports to plans only |
| Ohio | Two levels of analysis: encounter data completeness, for which two rates are calculated, and payment data accuracy — both aggregated across dental, institutional, professional and pharmacy claim types. | Performance metrics live in one contract appendix, compliance actions in another, which holds a compliance assessment system plus pre-determined financial and non-financial sanction tables. State rule allows temporary management on plans that repeatedly fail substantive requirements, and the plan pays the temporary manager's costs. | Architecture published, amounts not |
| New York | Monthly submission to the Medicaid Encounter Data System. That data drives utilization monitoring, access and continuity evaluation, quality indicators, risk adjustment and capitation rate setting. | On finding noncompliance the state issues either a statement of deficiency, for failure to comply with law or regulation, or a statement of finding, for failure to comply with the model contract. The plan then responds with a plan to correct. Liquidated damages for a late monthly submission appear in the model contract. | Structure published, amount unconfirmed |
| Tennessee | Systematic data quality edits and audits on submission, verifying data content and the accuracy of claims processing. Batches with fatal errors or failing defined threshold error rates rejected and returned within two business days. Industry clean-claim standards, HIPAA code sets, and integrity with all reference data sources including provider and member data. | Failure to adhere to the submission schedule may result in liquidated damages. The state's review software rejects only the problem encounters rather than whole batches — which means a small number of persistent rejects can sit unresolved without triggering anything obvious upstream. | Not published |
Where a state's penalty amounts are not publicly documented, this table says so rather than estimating. Encounter data standards change with each contract cycle. Full source list in the reading list below.
Where the pressure is
The table above is every contract. The pressure is not evenly distributed. Three states force the issue now — one by publishing the letter, one by publishing the grade, one by taking the money out of margin. Rank by the evidence problem, not by the size of last year's fine.
Named, quarterly, encounter-specific
AHCCCS publishes final sanction letters by plan and by quarter. Two clocks run at once: resolve every pend within 120 days, or a per-encounter sanction attaches; and an annual data-validation audit with a 5% threshold. Submission itself is 210 days from month-end. The dollars per pend are small. The operating system is not. Preliminary counts in published quarters have moved from five figures to zero when the plan already had the evidence.
Scored in public. Priced in 2027.
QMED 2.0 is live. Encounters submitted on or after January 1, 2026 are pass or fail each quarter, including uniqueness. Report cards are public. Fail one county and the plan fails the card. Monetary sanctions tied to that scoring begin July 1, 2027. DHCS can already act under APL 25-007. The expensive year is the one you are in, not the one with the fine schedule.
Unwaivable, and excluded from the MLR
HHSC posts the contractual maximum and the amount imposed, every quarter. Encounter standards cannot be waived. Liquidated damages are unallowable costs. The test is three-way: the 837, the 835 within 30 days, and the FSR reconciling to the warehouse. Then multiply by program and service area. A classification error in the encounter file is a rate and rebate problem, not only a submission problem.
The rest of the field is not gentler. Florida's liquidated-damages totals are real and mostly not encounter-only — do not read the FY2023–24 $33.2 million as an encounter number. New Jersey withholds capitation against monthly 2% denial and duplicate ceilings, then liquidates; the money does not come back. Washington publishes the document request itself: 120 encounters, 12 claim types, original claim, adjudicated claim, adjudication detail, final paid amount. That request is what defensibility has to produce. A plan in more than one of these states is not managing one compliance obligation.
What scales with plan size, and what doesn't
A reasonable question for anyone reading the table above: does a smaller plan get a smaller obligation? The published requirements answer it directly. Nearly every deadline, sample size and threshold in Medicaid encounter oversight is stated as a flat rule, identical for a plan with fifty thousand members and a plan with five million.
| Obligation | What it requires | Varies by plan size? |
|---|---|---|
| Encounter submission | 210 days from the end of the month of service or the date of enrollment, whichever is later (Arizona). | No |
| Pend resolution | 120 calendar days from the processing date, after which sanctions attach (Arizona). | No |
| Correction window | 63 days from notification; 45 days from adjudication to submit a valid claim (Oregon). | No |
| Batch return | Two business days to correct and resubmit a batch rejected for fatal errors or a failed threshold rate (Tennessee). | No |
| Error thresholds | Element omission and surplus at or below 5%, element accuracy at or above 95% (Arizona). Denial and duplicate rates each below 2%, monthly (New Jersey). 98% of 835s within 30 days of an accepted 837 (Texas). | No |
| Audit sample | 120 encounters across 12 claim types, each requiring the complete original and adjudicated claim at header and line level, plus adjudication detail and final paid amounts (Washington). | No |
| Challenge window | Roughly 30 days from preliminary findings to produce per-encounter evidence, for a service year that closed long before. | No |
| Independent audit | At least once every three years, of the accuracy, truthfulness and completeness of each plan's encounter and financial data (42 CFR 438.602(e)). | No |
| Data certification | A named individual attests to submitted encounter and financial data (42 CFR 438.604, 438.606). | No |
Two documented exceptions, and they point the same direction.
California writes the asymmetry into its own sanction-setting factors. Among the criteria DHCS weighs is the plan's financial status, including whether the sanction will impair its ability to come into compliance. That is a regulator formally acknowledging that the same penalty does not land the same way on every plan.
MACPAC's data shows where the cost actually sits. Of 359 corrective action plans issued across 25 states in one performance year, only 12 carried a financial penalty. KFF finds that when states do fine plans, the amounts are often very small relative to MCO revenues and profits. So for the overwhelming majority of accountability actions, the cost of a CAP is not the fine — it is the remediation labor required to close it, on the state's schedule, while normal operations continue.
Labor is the one input that does scale with the size of the organization. The obligation is flat; the capacity to absorb it is not. That is the whole of it, and every figure in the table above is publicly checkable.
The financial frame
| Figure | What it measures |
|---|---|
| 1% | Oregon's monthly administrative performance withhold on adjusted capitation, tied to the 45-day submission and 63-day correction standards. |
| 2% / 2% | New Jersey's monthly ceilings on encounter denial rate and duplicate encounter rate, measured separately. Miss either and capitation is withheld until resolved. |
| 98% in 30 days | Texas's 835 reconciliation standard against an accepted 837 with an internal control number, including adjustments and voids. |
| $33.2 million all categories |
Florida liquidated damages across 288 final actions in FY2023–24, spanning all compliance categories rather than encounter data alone, with damages levied against every contracted plan and desk reviews accounting for the majority. Do not read this as Florida's encounter-failure total. |
| ~$2.5 million | Kaiser Permanente's 2017 California sanction, in two components: $1,792,500 for failure to submit physician-administered drug data and $742,500 for failure to submit out-of-network encounter data. Not appealed. |
| 286 → 264 | Washington HCA's published 2024 Molina encounter data validation audit, initial findings to the revised final after reconsideration. |
| 11,116 → 2,852 | One Arizona plan's sanctionable pended encounters, preliminary count to final determination, for the December 2025 quarter — final sanction $51,845. Other published quarters show counts of 980 (ALTCS, June 2025) and 4,505 (ACC, December 2024) resolving to zero. Per-letter citations in the reading list; do not derive a per-encounter rate from the dollar figure, the formula is not visible in the letters. |
| Excluded from MLR | Texas treats liquidated damages as unallowable costs — neither medical expense nor premium payment. A data penalty comes straight out of administrative margin and cannot be recovered as a medical cost. |
What the state weighs when it sets a sanction
California publishes the factors it considers when deciding whether a CAP closes, continues, or escalates. They are among the clearest public statements of what regulators look for: the plan’s cooperation with the investigation; whether the plan aggravated or mitigated the injury; the corrective action taken to prevent recurrence; the plan’s financial condition, including whether a sanction would impair its ability to come into compliance; and the financial cost of the service denied, delayed, or modified.
The key factor is recurrence. Correcting the specific finding is only the starting point. What matters is whether the plan can show that the underlying cause has been fixed and that the same failure is unlikely to happen again. California requires monthly status updates with supporting documentation until the CAP is formally closed. A narrative update is not enough.
The sanction itself is often not the largest cost. The larger burden is the remediation required to satisfy the regulator, document the fix, and keep normal operations moving at the same time. A recent Medicare Advantage risk-adjustment matter illustrates the pattern, even though it involved a different program and a different enforcement mechanism: the threatened sanction was an enrollment freeze, while the remediation drove a nine-figure accrual. The dollar amount does not translate to Medicaid encounter data. The lesson does: the visible penalty is often only a fraction of the total cost.
The document request
What an auditor actually asks you for
This is the part plans consistently underestimate. The request is not for your encounter file. It's for everything behind your encounter file — and it arrives with a deadline measured in weeks, covering a service year that closed a long time ago.
A real encounter data validation request
Washington HCA, per its published final audit reports
- A random sample of 120 encounters representing 12 claim types — ten per claim type — drawn from a full calendar year of service dates.
- For each sampled encounter, the complete original network provider claim, including all header and line-level detail.
- The complete adjudicated claim, also with full header and line-level detail.
- The claim adjudication information.
- The final paid amounts.
HCA's published 2024 Molina EDV final notice states the sample in those terms — 120 encounters, twelve claim types, ten per type, service dates in calendar 2021 — and reduced findings on reconsideration from 286 to 264. Other published HCA EDV reports show the same sample architecture. Source: 2024 MHW EDV Final Notice and Report.
The lesson in those numbers
Findings move. In Arizona, one plan's sanctionable pended encounters went from a preliminary count of 11,116 to a final determination of 2,852 in a single quarter. In other published quarters, preliminary counts of 4,505 and 980 resolved to zero. In Washington, a published 2024 EDV report moved from 286 findings to 264 on reconsideration.
That gap between preliminary and final is not luck. It is the plan producing evidence inside the challenge window — and the plans that produce it are the plans that already had it. Nobody reconstructs a year of claim-to-encounter lineage in thirty days from a standing start.
Which reframes the whole problem. The question is not whether your data is clean. It's whether you can demonstrate it is clean, per encounter, on demand, for a service year that closed eighteen months ago — and whether you can show the remediation trail for the ones that weren't.
HCA may impose sanctions if the Contractor fails to meet one or more of its obligations under this Contract, a CAP, or applicable law, including but not limited to submitting reports, documents, data, or any other information that is inaccurate, incomplete, untruthful, or untimely.
Washington State Health Care Authority managed care contract
The capability underneath
Reporting tells you what happened. Audit defensibility proves why.
Most plans respond to audit pressure by building better reports. That helps, but only to a point. A report is downstream of the underlying transaction. If the connection between the paid claim and the submitted encounter was not captured at the time, a later report cannot recreate it. And that connection is exactly what an auditor will ask you to prove.
What audit defensibility actually means
We sometimes call it "audit insurance," but it is not a product or a financial instrument. It is an operating capability: the ability to prove, on demand, what happened to a specific member, claim, or encounter.
That means being able to show who the member was, what eligibility information was available on the date of service, what the claim relied on when it adjudicated, what provider data was used, whether any retroactive change occurred and when, whether the encounter passed state and T-MSIS checks, and what action was taken, by whom, on which record.
Most of this information usually exists somewhere. The issue is whether your team can assemble it quickly, consistently, and in a form that will stand up to review — or whether it takes heroic manual effort under a thirty-day deadline.
UniSync
A conformance-and-reconciliation layer for managed care operations. It conforms, reconciles and trust-scores operational data across the systems you already run, and it runs alongside production — no core migration, no rip and replace. What it produces is a defensible, point-in-time record of what was received, transformed, submitted, returned, and resolved.
EncounterCURE
Encounter lifecycle management against each state's actual rules. Pends surfaced while the resolution clock is still open. Voids tracked through to resubmission. 837 and 835 reconciliation maintained as a standing state rather than a quarterly scramble. Per-encounter lineage back to the adjudicated claim.
EnrollmentCURE
Daily enrollment processing and 834 reconciliation between the state file and your membership system, with retroactive adds, drops and reinstatements tracked to resolution — including the capitation consequences. Built for the redetermination volume arriving in 2027, not the volume of 2019.
Every deployment is configured to the client's environment — their state contracts, their submission windows, their source systems, their reconciliation rules. There is no generic version of this, because there is no generic state.
What it looks like when the record already exists
Client identity withheld at the client's request. Results drawn from the plan's own audit findings and state sanction determinations. A second proof point will land on this page when it is cleared.
Zero sanctions and clean audit findings two consecutive years — the first time in the plan's history
This plan operates in one of the few states that assesses encounter sanctions quarterly and publishes the results by name. Before the engagement, pended encounters were surfacing after the resolution window had already closed, and the evidence needed to challenge a preliminary finding had to be assembled by hand, per encounter, after the fact.
The change was not a better report. It was making claim-to-encounter lineage a standing property of the data — so a pend is visible while the clock is still running, and the documentation supporting every submitted encounter already exists when the state asks for it.
Delivered on: UniSync, with EncounterCURE and EnrollmentCURE modules configured to the plan's specific state contracts, submission windows and source systems.
Webinar
Surviving the Encounter Data Audit: What Sanction-Free Actually Requires
How state encounter enforcement really escalates, what an auditor's document request looks like in practice, and what sanction-free actually requires of the record.
What's covered
- Why an audit you don't control still becomes your evidence problem.
- The escalation ladder: notice of concern, notice to cure, CAP, sanction — and what stops it at each stage.
- The real document request a state sends, item by item.
- What the H.R.1 enrollment changes do to the same data layer in 2027.
- How to become audit-ready without a huge system overhaul.
- Prepared Q&A: challenge windows, CAP close-out, and where to start with limited resources.
Presented by CureIS Data and AI Architect, Gabe Madril.
From the CureIS blog
Before Claims AI, Build the Record an Auditor Would Trust
The argument underneath this entire page. Why claims looks like the obvious first AI pilot and is usually the wrong one, the five-question test for picking a safe first move, and what audit defensibility requires operationally — including the seam-by-seam trust-scoring exercise you can run on your own 90-day population.
The muscle memory of evidentiary backing — where a decision came from, what data supported it, and how far you could trust it — is exactly the skill set a successful AI capability is built on. And there's no cheap shortcut to it.
Bret Randolph, Chief Operating Officer, CureIS Healthcare
Readiness self-assessment quiz
Eight questions an auditor will effectively ask you
Instant read-out. Your answers are not collected or stored by us. If most of them are guesses, that's your assessment.
Reading list
The source material
Federal framework, independent research, and the state primary sources behind every figure on this page.
Federal framework
- 42 CFR Part 438 — Managed Care eCFR · Subpart I holds sanctions: § 438.700 grounds, § 438.704 penalty amounts. See also § 438.242 health information systems, § 438.602(e) independent audit, §§ 438.604 and 438.606 data certification
- T-MSIS data quality and compliance Medicaid.gov · compliance actions resumed September 1, 2025 per the CMS State Health Official letter of May 28, 2025. More than 6,000 data quality checks, scored through the Outcomes-Based Assessment framework
- Medicaid Encounter Data Toolkit CMS (PDF) · practitioner guide including comparative state performance standards
- State Toolkit for Validating Encounter Data CMS (PDF)
- CMS encounter data guidance Medicaid.gov · including the position that federal matching payments should not be made for individuals whose encounter data a state does not report
- SMD #26-001 — Six-month redeterminations CMS · March 6, 2026 (PDF) · H.R.1 § 71107, including the ex parte requirement and minimum notice floors
- Medicaid Managed Care: Additional CMS Actions Needed to Help Ensure Data Reliability GAO-19-10 · the foundational federal finding on encounter data reliability
Independent research
- June 2026 Report to Congress, Chapter 3: Managed Care Accountability MACPAC · most current authority. Reviewed 34 states' MCPARs for performance year 2023: 359 CAPs issued by 25 states, 106 civil monetary penalties by 11 states, 187 liquidated-damages actions by 10 states, and only 12 of the 359 CAPs carrying a financial penalty. Also the finding that accountability reporting lacks consistent definitions
- Revisiting Managed Care Sanctions National Health Law Program · July 2025 · ten-state review built on Managed Care Program Annual Reports. Documents pended encounters as a recurring, named basis for Arizona's sanctions
- Managed Care Sanctions: An Important Tool for Accountability National Health Law Program · December 2022 · the predecessor study
- Data for Program Accountability and Policy Development MACPAC · the clearest short statement of the two federal levers
- Medicaid Managed Care Network Adequacy & Access: Current Standards and Proposed Changes KFF · source for the finding that 9 of 38 managed care states reported issuing any monetary or non-monetary penalty for network adequacy noncompliance over three years, excluding CAPs — and that fines are often small relative to MCO revenues and profits
- Medicaid Program Integrity: Tracking State-Specific and Nationwide Federal Action KFF · live tracker of federal program integrity actions by state
- What to Know About Recent Federal Actions Involving State Medicaid Program Integrity KFF
- How States Can Improve Medicaid Encounter Data Health Affairs Forefront
State primary sources
- AHCCCS Administrative Actions Arizona · published final sanction letters by plan and quarter. The most transparent encounter-data enforcement record in the country
- ACOM Policy 408 — Sanctions Arizona (PDF) · the escalation ladder. Companion: the Encounter Manual (rev. 10/31/2024) for both the 210-day submission window and the 120-day pend resolution clock
- Final Results of Sanctionable Pended Encounters, December 2025 (ACC) Arizona (PDF) · the 11,116 → 2,852 letter, final sanction $51,845, signed May 11, 2026. Companion: the June 2025 ALTCS letter showing 980 resolving to zero
- APL 26-003 — Encounter Data Quality (QMED 2.0) California (PDF) · quarterly pass/fail from January 2026; monetary sanctions from July 2027
- APL 25-007 — Enforcement Actions: CAPs and Sanctions California (PDF) · the sanction-setting factors and CAP monitoring cadence. Imposed actions at DHCS sanction letters
- HHSC Managed Care Organization Sanctions Texas · quarterly postings that publish both the maximum available sanction and the amount actually imposed. Encounter standards in UMCM 5.12.2
- HCA Audits and Reporting Washington · per-plan final audit reports including encounter data validation, published because 42 CFR 438.602 requires it. Sample architecture in the 2024 Molina EDV final notice (120 encounters, 12 claim types)
- AHCA Data and Reports Florida · per-plan compliance dashboards with dollar totals by category
- OAR 410-141-3570 — Encounter submission Oregon · the 45-day rule, including encounters where the plan determined liability exists even if it paid nothing. Validation program at the state's EQRO
Find your own state. Search your state Medicaid agency site for "encounter data validation," "sanctions," or "administrative actions." Agencies that publish do so inconsistently — sometimes under oversight, sometimes under program integrity, sometimes only in the annual managed care report.
Plain English
Glossary
- Encounter
- The record a plan sends the state for a service it was financially liable for. Not the same thing as the claim it paid — it is a separate submission, in the state's format, inside the state's window, and it is what gets audited.
- Pend
- An encounter the state accepted into its system but could not fully process, usually because something failed an edit. It sits waiting. Arizona gives plans 120 calendar days from the processing date to clear it.
- Void and replace
- Withdrawing a submitted encounter and sending a corrected one. The failure mode is voiding without resubmitting, which Arizona explicitly defines as an omission error when the underlying claim still shows as paid.
- Encounter data validation (EDV)
- The audit itself. The state samples encounters and compares them against the plan's own paid claim file and source documentation, measuring omission, element omission, element surplus, and element accuracy.
- Encounter omission error
- A service the plan was financially liable for but never submitted — or one it voided and never resubmitted. The most expensive category, because it understates your population.
- Corrective action plan (CAP)
- A documented remediation plan the state approves and monitors. Not a penalty. By far the most common state response, and the stage where most matters actually end.
- Liquidated damages
- Contractual, and framed by states as a reasonable estimate of their projected financial loss rather than punishment. New Jersey's are cost-based, set to make the state whole, which is why no fee schedule exists there.
- Sanction
- The penalty. Civil money penalty, capitation withhold, suspension of new enrollment, permitting enrollees to transfer out, temporary management, or contract termination.
- Capitation withhold
- The state keeps a slice of what it owes you until you comply. Oregon withholds 1% of adjusted capitation monthly against its submission standards. In New Jersey, withheld amounts eventually become non-recoverable.
- T-MSIS
- The federal data system states report Medicaid data into. More than 6,000 data quality checks. Compliance actions resumed September 1, 2025, and repeated monthly misses can put the state under a CAP — which the state then pushes down to its plans.
- Data lineage
- The traceable path from the claim you received, through adjudication, to the encounter you submitted, to what the state returned, to what you did about it. The thing an auditor is actually asking for.
- Audit defensibility
- The operational ability to prove, on demand, what the plan knew, when it knew it, which system it came from, and what action followed. We sometimes call it audit insurance.
Questions we get asked
Straight answers
What actually triggers a sanction against a Medicaid plan?
Grounds for federal sanctions are listed in 42 CFR 438.700 and include misrepresenting or falsifying information furnished to CMS or the state — a ground that sits in the higher penalty tier under 42 CFR 438.704.
In practice, most Medicaid sanctions are contractual and state-imposed rather than federal. The most common documented triggers are encounter data that is late, incomplete, duplicated, or unresolved after the state flagged it; network adequacy failures; performance measure shortfalls; and untimely provider payment. Arizona's published record shows unresolved pended encounters as its most frequent basis.
What's the difference between a CAP, liquidated damages, and a sanction?
A corrective action plan is a documented remediation plan the state approves and monitors. It is not a penalty, and it is the most common state response by a wide margin. Reviewing 34 states' managed care program annual reports for performance year 2023, MACPAC counted 359 CAPs issued by 25 states — against 106 civil monetary penalties from 11 states and 187 liquidated-damages actions from 10 states. Only 12 of those 359 CAPs carried a financial penalty at all.
Liquidated damages are contractual, and states describe them as reasonable estimates of their projected financial loss rather than punishment. Florida draws that distinction explicitly.
Sanctions are the penalties. One caution when comparing states: MACPAC found at least one state that imposed liquidated damages but did not report them as sanctions, because it did not classify them that way. The categories are not applied consistently.
How long do we actually have to fix a pended encounter?
It depends entirely on the state, and the windows are shorter than most plans assume. Arizona requires all pended encounters resolved within 120 calendar days of the processing date. Oregon requires corrections within 63 days of notification and valid claims submitted within 45 days of adjudication. Tennessee returns rejected batches within two business days. Texas requires 98% of 835 transactions within 30 days of an accepted 837.
The operational problem is rarely the length of the window. It's that the pend often isn't visible to the people who could resolve it until the window has closed.
Can we challenge a preliminary audit finding?
Yes, and the published record shows it works — when you have the evidence. States generally issue preliminary findings, open a challenge window, then issue a final report on which sanctions are assessed. In Washington, HCA's published 2024 Molina EDV report reduced findings on reconsideration from 286 to 264. In Arizona, published quarters show preliminary sanctionable pend counts of 11,116 resolving to 2,852, and counts of 4,505 and 980 resolving to zero.
The constraint is that a challenge window is typically about thirty days and covers a service year that closed long ago. Plans that win these have per-encounter documentation already in hand. Nobody builds it from scratch inside the window.
Our claims data is clean. Why would our encounter data fail?
Because the state isn't auditing whether you paid the claim. It's auditing whether the record you sent the state matches the claim you actually paid, in the state's format, inside the state's window — and then whether you can prove it per encounter.
The failure modes live between systems: an encounter voided and never resubmitted while the claim still shows as paid; a pend resolved in the claims system but never returned to the state; provider or member reference data out of sync; an 837 accepted but its 835 never reconciled. Kaiser Permanente's own stated explanation for its approximately $2.5 million California sanction was that its systems were built for quality, access and integration of care and were never designed to collect information in the format the state required.
How much does a data sanction actually cost?
The fine is usually the smallest number. Both KFF and the National Health Law Program find Medicaid managed care fines are often very small relative to plan revenues.
The larger exposure is elsewhere. Encounter data feeds risk adjustment and capitation rate setting, so understated encounters understate the cost of your population in the rate you're paid for years — Washington's state auditor said plainly that incomplete or inaccurate information could affect premium rate accuracy. Damages can't be passed through: Texas treats them as unallowable costs, excluded from the MLR calculation. In New Jersey, withheld capitation becomes non-recoverable once liquidated.
And remediation dominates. The sharpest illustration comes from a different program: in a 2026 Medicare Advantage risk-adjustment matter, CMS threatened enrollment and marketing sanctions over years of diagnosis corrections submitted outside the required systems. The threatened penalty was an enrollment freeze; the remediation produced a roughly $935 million accrual. Encounter validation works differently, but the ratio holds — the penalty is the visible cost and rarely the largest one.
Does H.R.1 create new encounter data requirements?
No. H.R.1's data provisions are about eligibility verification — addresses and Social Security numbers, Death Master File checks, cross-state duplicate screening, and more frequent redeterminations. Encounter data obligations are separate, older, and enforced through state contracts, T-MSIS reporting, and the federal match.
The connection is operational. Six-month redeterminations for expansion adults, effective for renewals scheduled on or after January 1, 2027, roughly double redetermination volume and therefore the retroactive adds, drops and reinstatements moving through 834 reconciliation and capitation. That's the same enrollment record an auditor will eventually ask you to substantiate, and the same data layer that feeds encounters. The H.R.1 resource center covers that side in full.
We have limited resources. Where's the most leverage?
Lineage on one thing, rather than a plan-wide assessment. Pick a single state contract and a single claim type, and establish whether you can trace every submitted encounter back to its adjudicated claim, and every pend to its resolution, without anyone assembling it by hand.
If you can't, that's the finding — and it's more useful than a hundred-page readiness report, because it's the exact thing the audit will test.
Should we build this ourselves or bring in help?
It depends on your IT capacity and your runway. Continuous reconciliation and per-encounter lineage are real engineering work but entirely solvable, and plans with strong internal teams have built them. The catch is that a prototype answers the easy question — can we generate something useful from clean data — while production has to answer the hard one: can we generate something accurate, repeatable, traceable, and defensible from the data we actually run on, across delayed feeds, manual adjustments, retroactive changes, and rules that live in people's heads.
Either way the requirement is the same: conformed data, continuous reconciliation, and an audit trail.
What's the first step if we think we're exposed?
Take a recent 90-day population and ask four questions. How often did eligibility on the date of service disagree with the claim? How often did retroactive changes land after payment? How often did encounters fail for knowable reasons? And how much manual effort did reconstruction take?
That's your baseline, and it's four answers rather than a project. Then find out when your last data validation audit was and what it actually found — a surprising number of plans don't know.
One move you can make this week
Find out whether you could trace one encounter end to end
Pick a single state contract and a single claim type. If producing the original claim, the adjudicated claim, the adjudication detail, and the final paid amount takes a person more than a few minutes, that's your starting line — because that is the actual document request.
Not sure where to start? Sit down with us. One of our analysts will walk your claim-to-encounter path end to end and show you exactly where you stand. No commitment, and a real person, not a bot.
CureIS has spent nearly two decades inside managed care data and claims operations, running daily enrollment processing and encounter operations for leading health plans and systems in Arizona, California and elsewhere. Our EncounterCURE and EnrollmentCURE modules handle the encounter lifecycle and daily enrollment processing, and UniSync continuously conforms, reconciles and trust-scores the data underneath. CureIS tools work alongside the core systems you already run, including Facets, QNXT and HealthRules. No rip and replace. Implementation in weeks.