RESOURCE CENTER

Audits, CAPs, Sanctions, and Your Encounter Data

Audits don’t start with an auditor. They originate eighteen months earlier in a pended encounter that wasn’t resolved and an 834 reconciliation no one documented. By the time the notice arrives, the record either exists as proof which a plan can provide promptly, and that an auditor can trust. Or it doesn’t. And the compliance runway is shorter than the relevant calendar dates suggest.

California has been scoring every plan’s encounter data quarterly since January 2026 and posts the report cards publicly. But the monetary sanctions tied to that scoring don’t begin until July 1, 2027. In other words, CA plans are being graded, on the record, months before the grades carry a price. In Arizona, sanction letters by plan have been published quarterly for more than fifteen years. From January 1, 2027, the H.R.1 enrollment provisions double redetermination volume through the same data layer that feeds encounters.

State agencies sanction in escalating phases: notice of concern, notice to cure, mandated corrective action plan, then sanction. Each stage offers plans a window to produce the necessary evidence within a deadline. CMS resumed T-MSIS data-quality compliance actions in September 2025. While formal accountability to meet the federal floor rests with the state, the operational pressure lands on the plan, because the plan holds the only copy of the evidence.

This page explores how enforcement actually works, what auditors ask a plan to produce, how ten states differ, and what a plan can do now to ensure audit defensibility or to triage a sanctions challenge already underway.

How Enforcement Works

There’s no single national answer to “what happens if our encounter data is late?” Two federal provisions create the floor. Each state then builds its own machinery on top of these.

 Federal Floor

42 CFR 438 plus T-MSIS

Federal rules require plans to maintain a health information system that collects, analyzes, and reports encounter data, and require the state to validate it. 42 CFR 438.602(e) puts an independent audit on a three-year clock. T-MSIS is how CMS scores what the state then reports. The same statute applies everywhere, but it doesn’t provide the clock, the threshold, or the penalty.

State Machinery

Each state builds its own physics

42 CFR 438.700 lists the grounds for sanctions, including misrepresenting or falsifying information furnished to CMS or the state (a ground in the higher civil money penalty tier under 438.704). Plans operate inside the state contract terms: Oregon’s 1% monthly withhold, New Jersey’s withhold-then-liquidate, Arizona’s 120-day pend clock, Texas’s unwaivable liquidated damages.

The escalation ladder

Arizona writes this down explicitly in its sanctions policy, and MACPAC found the same pattern in its review of 34 states’ managed care program annual reports: agencies reach for corrective action long before they reach for a fine.

Links: Ladder as published in AHCCCS ACOM Policy 408, Sanctions. Escalation pattern across states documented in MACPAC’s June 2026 Report to Congress, Chapter 3.

Public visibility varies

Medicaid managed care enforcement is contractual and state-administered. 42 CFR 438.66(e) only requires the state to report sanctions and corrective actions in an annual report at the end of the contract year, and the Medicaid statute doesn’t require timely public reporting of plan sanctions at all.

Medicare Advantage enforcement is publicly visible because CMS publishes notices when issued. On the Medicaid side, per KFF, enforcement is slower to surface and leans heavily on corrective action plans (CAPs) rather than fines: fewer than a quarter of managed care states reported issuing any monetary or non-monetary penalty for network adequacy noncompliance over a three-year period, excluding CAPs.

Arizona is the conspicuous exception. AHCCCS publishes individual final sanction letters for encounter data noncompliance, quarterly by plan, going back more than fifteen years. These published letters make pended encounters a visible, recurring basis for sanction, and they are not its only basis. AHCCCS also sanctions for data validation failures, accreditation, and administrative cost percentage.

The rest of the country is less visible, which poses a problem for plans relying on the news to estimate their own exposure.

How Plans Are Affected

Plans don’t run the audit, set submission windows, or write the error thresholds. But the plan is the only party that can produce the evidence, and pays when it can’t.

Clean claims and clean encounters are not the same file. A plan can adjudicate correctly, pay providers on time, and still fail an encounter audit because the state isn’t auditing whether you paid the claim. It’s auditing whether the record you sent the state matches the claim you actually paid, in the state’s format, inside the state’s window, per encounter. Most plan architectures were built to handle only part of the puzzle.

Claims automation on untrustworthy data is high risk. Your first move is to find out what your data would say to an auditor, a state reviewer, or a model – before someone else does.

Chris Sawotin, Chief Executive Officer, CureIS Healthcare

How the burden moves

The requirement is written at the top. The evidence only exists in the middle.

What fails

Encounter side

Six failure modes states measure

Pends that age out. Arizona contractors must resolve all pended encounters within 120 calendar days of the processing date. When AHCCCS acknowledges its own error and releases corrected codes a new 120-day clock starts — but only if the plan notified AHCCCS in writing that resolution depended on the state. Silence forfeits the exception.

Voids that never came back. Arizona’s definition of an encounter omission error explicitly includes an encounter inappropriately voided and not resubmitted while still appearing as a paid claim. Nothing in the claims system will flag that.

Batches failing threshold error rates. TennCare subjects every submission to edits verifying not only data content but the accuracy of claims processing. Fatal errors or a failed threshold rate means rejection and return within two business days.

835s never reconciled to the accepted 837. Texas requires 98% of 835 transactions within 30 days of an accepted 837 carrying an internal control number — including adjustments and voids.

Denial and duplicate rates. New Jersey holds plans below 2% on each, measured separately, every month.

Reference data drift. TennCare requires plans to maintain integrity with all reference data sources, including provider and member data. That is where a stale provider identifier stops being hygiene and becomes a contract term.

Enrollment side

The newer, less-mapped exposure

Somebody signs for it. The consequence of a data failure is not only a finding — it is that a named person attested to data that turned out not to hold. 42 CFR 438.604 and 438.606 require a named individual to certify the encounter and financial data the plan submits. False Claims Act matters in adjacent programs have included allegations that plans certified data that did not hold. The program may differ; the certification exposure is the same shape.

Addresses become a plan obligation. Under H.R.1 § 71103, effective January 1, 2027, states must collect enrollee addresses and Social Security numbers and establish a process to regularly obtain address information. California’s implementation plan names managed care organizations explicitly as an address verification source, alongside USPS return mail and the National Change of Address database.

Quarterly death file checks, and their false positives. H.R.1 § 71104 requires quarterly verification against the SSA Death Master File and disenrollment on a match — and immediate reenrollment, retroactive to the erroneous disenrollment date, for anyone dropped in error. California reads this as requiring resolution rather than automatic termination, because false-positive matches are common. Every retroactive correction has to reconcile cleanly through enrollment, capitation, and encounters.

Twice the churn through the same pipeline. Six-month redeterminations double the retroactive adds, drops, and reinstatements moving through 834 reconciliation — the same enrollment record an auditor will eventually ask you to substantiate.

See the enrollment side in full →

Where Things Stand

September 2026

Enforcement in this area moves in lag.

The federal clock restarted

T-MSIS compliance actions resumed a year ago.

T-MSIS data-quality compliance actions resumed September 1, 2025. Under SHO 25-002 the escalation is two steps, not one: miss quality targets for two consecutive months and CMS notifies the state of potential risk; miss two additional consecutive months and CMS sends a letter requesting a corrective action plan within 30 days. File layout version 4 is expected in production by September 30, 2026. The accountability is the state's. The data is yours.

California starts measuring now, fining later

QMED 2.0 is live. Monetary sanctions begin July 2027.

Under APL 26-003, encounters submitted on or after January 1, 2026 are measured quarterly as pass or fail, across completeness, accuracy, reasonability, timeliness and uniqueness. DHCS began posting quarterly report cards publicly no earlier than April 1, 2026. Enforcement specific to QMED 2.0, including its monetary sanctions, starts July 1, 2027 — so plans have roughly one more measurement year on the public record before the scoring itself carries a price. DHCS retains its existing enforcement authority under APL 25-007 in the meantime.

CMS program-integrity deferrals in 2026 targeted state-claimed expenditures, not any plan's encounter file. They still matter here for one reason: when a state has to document what it paid for, it comes asking the plans. The plan holds the only copy of the evidence.

Worth watching on the encounter side. MACPAC's June 2026 report found that federal reporting requirements for accountability actions lack clear definitions, so states report inconsistently — at least one state imposed liquidated damages but did not report them as sanctions because it did not classify them that way. MACPAC has recommended CMS issue guidance on consistent reporting. If that lands, the enforcement picture gets far more visible than it is today, which cuts both ways for a plan.

Fact Sheet

Audits, CAPs and sanctions by numbers and dates

Key details, effective dates, state-by-state mechanics, and sources. Every figure below traces to a state contract, administrative rule, agency policy manual, or published audit report.

120 days Arizona's window to resolve a pended encounter, from the processing date, before sanctions attach
5.0% Arizona data validation threshold. At or below, no sanction applies. Element accuracy at or above 95% is high
359 Corrective action plans issued by 25 states in one performance year. MACPAC reviewed 34-state MCPARs. States reach for a CAP far more often than a fine
3 years Maximum interval between independent audits of each plan's encounter and financial data, per 42 CFR 438.602(e)

Sources: AHCCCS Encounter Manual and Annual Data Validation Audit findings; MACPAC June 2026 Report to Congress, Chapter 3 (MCPAR review, performance year 2023, 34 states); 42 CFR 438.602(e).

Key dates

Dates most likely to touch plan encounter and enrollment operations. Confirm state-specific timing against your operative contract.
WhenWhat happens
May 28, 2025 CMS issues a State Health Official letter on T-MSIS data-reporting compliance.
Sep 1, 2025 T-MSIS data-quality compliance actions resume. Per SHO 25-002, escalation runs in two steps: two consecutive months missing quality targets triggers a CMS notice of potential risk, and two additional consecutive months triggers a letter requesting a corrective action plan within 30 days.
Jan 1, 2026 California begins measuring encounter data quality quarterly as pass or fail under QMED 2.0, per APL 26-003.
Apr 1, 2026 Earliest date DHCS begins publicly posting quarterly QMED 2.0 report cards by plan.
Jun 2026 MACPAC's June Report to Congress, Chapter 3, publishes the 34-state accountability review and recommends CMS issue guidance on consistent reporting of sanctions, liquidated damages, and informal interventions.
Sep 30, 2026 T-MSIS file layout version 4 expected in production.
Jan 1, 2027 H.R.1 enrollment provisions land together. Addresses and SSNs collected and furnished to the Secretary (§ 71103). Quarterly Death Master File verification with retroactive reenrollment on erroneous disenrollment (§ 71104). Six-month redeterminations begin for renewals scheduled on or after this date (§ 71107).
Jul 1, 2027 California enforcement specific to QMED 2.0, including monetary sanctions, begins. Consistent with APL 25-007.
Jan 1, 2028 H.R.1 § 71105 provider and supplier Death Master File checks take effect. Not to be confused with the enrollee checks a year earlier.
Oct 1, 2029 The Secretary must establish a centralized enrollment verification system letting states cross-check for multi-state enrollment (§ 71103).

Ten states, ten different ways to be wrong

Same federal floor. No national encounter data standard underneath it. Every state sets its own submission window, its own error thresholds, its own penalty mechanism, and decides for itself whether any of it becomes public. A plan operating in more than one state is not managing one compliance obligation. It is managing a different one per contract.

State The standard that's measured How the penalty works Public record
Arizona Two separate clocks. Encounters must be submitted within 210 days of the end of the month of service or the date of enrollment, whichever is later. Once submitted, all pended encounters must be resolved within 120 calendar days of the processing date — that second clock is the sanction trigger. Separately, an annual data validation audit measuring encounter omission, element omission, element surplus and element accuracy, by professional and facility form type. Pended-encounter sanctions assessed quarterly on a count basis. Validation studies can produce a sanction, a required CAP, or both; at or below the 5% threshold, no sanction applies. State rule also allows suspension of further member enrollment and a monetary sanction against capitation prepayment. Letters published quarterly
California Encounters submitted on or after January 1, 2026 measured quarterly as pass or fail under QMED 2.0, across completeness, accuracy, reasonability, timeliness and uniqueness. DHCS materials also reference consistency — check the current methodology document rather than assuming the legacy four. Public quarterly report cards from April 2026; QMED 2.0 monetary sanctions from July 1, 2027. State law allows up to $25,000 first violation, $50,000 second, $100,000 each subsequent — assessable per day, and per affected beneficiary. Sanction letters published
Texas 98% of all 835 transactions within 30 days of an accepted 837 encounter carrying an internal control number, including adjustments and voids. Encounters submitted monthly. Liquidated damages up to $5,000 for a first quarter of claims-processing noncompliance, up to $25,000 per quarter after. Encounter data is on the list of standards for which the state cannot waive damages. Damages are unallowable costs, excluded from the medical loss ratio. Posted quarterly, with maximums
Florida Statute requires compliance with Medicaid Encounter Data System reporting, HIPAA-compliant electronic format, and agency deadlines. Three tracked action types: corrective action plans, liquidated damages, and sanctions. The state's framing is that damages are not punitive but estimates of its projected loss. In FY2023–24, 288 final actions produced $33.2 million in liquidated damages across all compliance categories, not encounter-only, and every contracted plan had damages levied against it. One plan's desk review drove most of the single largest total. Per-plan dashboards
Washington Encounter data submitted at minimum monthly, no later than 30 calendar days from the end of the month the plan paid the liability. Clean claims: 99% within 90 days of receipt. Contract language is unusually broad — the state may sanction for submitting reports, documents, data or any other information that is inaccurate, incomplete, untruthful or untimely. Failure to meet a CAP's terms opens sanctions, liquidated damages, or any other remedy allowed. Final audit reports published
Oregon Valid claims submitted within 45 days of adjudication, and encounter data requiring correction fixed within 63 days of notification. Includes encounters where the plan determined liability exists even if it paid nothing. An administrative performance withhold equal to 1% of the adjusted capitation payment for the subject month, assessed monthly. Distinct from the quality pool withhold. An external review organization has run encounter data validation since 2020, including medical record review against submitted encounters. EQRO validation reports
New Jersey Encounter denial rate below 2% and duplicate encounter rate below 2%, measured separately, monthly. Required data quality assurance plan covering timely capture, accuracy, completeness, and internal audit procedures. Withhold then liquidate: failure initially withholds capitation until resolved; if standards still aren't met after a specified period, the withheld amounts are liquidated and not recoverable. Damages are cost-based, set to make the state whole, which is why no fee schedule exists. State rule also permits suspending new enrollment and letting enrollees transfer out without cause. Monthly reports to plans only
Ohio Two levels of analysis: encounter data completeness, for which two rates are calculated, and payment data accuracy — both aggregated across dental, institutional, professional and pharmacy claim types. Performance metrics live in one contract appendix, compliance actions in another, which holds a compliance assessment system plus pre-determined financial and non-financial sanction tables. State rule allows temporary management on plans that repeatedly fail substantive requirements, and the plan pays the temporary manager's costs. Architecture published, amounts not
New York Monthly submission to the Medicaid Encounter Data System. That data drives utilization monitoring, access and continuity evaluation, quality indicators, risk adjustment and capitation rate setting. On finding noncompliance the state issues either a statement of deficiency, for failure to comply with law or regulation, or a statement of finding, for failure to comply with the model contract. The plan then responds with a plan to correct. Liquidated damages for a late monthly submission appear in the model contract. Structure published, amount unconfirmed
Tennessee Systematic data quality edits and audits on submission, verifying data content and the accuracy of claims processing. Batches with fatal errors or failing defined threshold error rates rejected and returned within two business days. Industry clean-claim standards, HIPAA code sets, and integrity with all reference data sources including provider and member data. Failure to adhere to the submission schedule may result in liquidated damages. The state's review software rejects only the problem encounters rather than whole batches — which means a small number of persistent rejects can sit unresolved without triggering anything obvious upstream. Not published

Where a state's penalty amounts are not publicly documented, this table says so rather than estimating. Encounter data standards change with each contract cycle. Full source list in the reading list below.

Where the pressure is

The table above is every contract. The pressure is not evenly distributed. Three states force the issue now — one by publishing the letter, one by publishing the grade, one by taking the money out of margin. Rank by the evidence problem, not by the size of last year's fine.

Arizona · the letter

Named, quarterly, encounter-specific

AHCCCS publishes final sanction letters by plan and by quarter. Two clocks run at once: resolve every pend within 120 days, or a per-encounter sanction attaches; and an annual data-validation audit with a 5% threshold. Submission itself is 210 days from month-end. The dollars per pend are small. The operating system is not. Preliminary counts in published quarters have moved from five figures to zero when the plan already had the evidence.

California · the grade

Scored in public. Priced in 2027.

QMED 2.0 is live. Encounters submitted on or after January 1, 2026 are pass or fail each quarter, including uniqueness. Report cards are public. Fail one county and the plan fails the card. Monetary sanctions tied to that scoring begin July 1, 2027. DHCS can already act under APL 25-007. The expensive year is the one you are in, not the one with the fine schedule.

Texas · the margin

Unwaivable, and excluded from the MLR

HHSC posts the contractual maximum and the amount imposed, every quarter. Encounter standards cannot be waived. Liquidated damages are unallowable costs. The test is three-way: the 837, the 835 within 30 days, and the FSR reconciling to the warehouse. Then multiply by program and service area. A classification error in the encounter file is a rate and rebate problem, not only a submission problem.

The rest of the field is not gentler. Florida's liquidated-damages totals are real and mostly not encounter-only — do not read the FY2023–24 $33.2 million as an encounter number. New Jersey withholds capitation against monthly 2% denial and duplicate ceilings, then liquidates; the money does not come back. Washington publishes the document request itself: 120 encounters, 12 claim types, original claim, adjudicated claim, adjudication detail, final paid amount. That request is what defensibility has to produce. A plan in more than one of these states is not managing one compliance obligation.

What scales with plan size, and what doesn't

A reasonable question for anyone reading the table above: does a smaller plan get a smaller obligation? The published requirements answer it directly. Nearly every deadline, sample size and threshold in Medicaid encounter oversight is stated as a flat rule, identical for a plan with fifty thousand members and a plan with five million.

Obligation What it requires Varies by plan size?
Encounter submission 210 days from the end of the month of service or the date of enrollment, whichever is later (Arizona). No
Pend resolution 120 calendar days from the processing date, after which sanctions attach (Arizona). No
Correction window 63 days from notification; 45 days from adjudication to submit a valid claim (Oregon). No
Batch return Two business days to correct and resubmit a batch rejected for fatal errors or a failed threshold rate (Tennessee). No
Error thresholds Element omission and surplus at or below 5%, element accuracy at or above 95% (Arizona). Denial and duplicate rates each below 2%, monthly (New Jersey). 98% of 835s within 30 days of an accepted 837 (Texas). No
Audit sample 120 encounters across 12 claim types, each requiring the complete original and adjudicated claim at header and line level, plus adjudication detail and final paid amounts (Washington). No
Challenge window Roughly 30 days from preliminary findings to produce per-encounter evidence, for a service year that closed long before. No
Independent audit At least once every three years, of the accuracy, truthfulness and completeness of each plan's encounter and financial data (42 CFR 438.602(e)). No
Data certification A named individual attests to submitted encounter and financial data (42 CFR 438.604, 438.606). No

Two documented exceptions, and they point the same direction.

California writes the asymmetry into its own sanction-setting factors. Among the criteria DHCS weighs is the plan's financial status, including whether the sanction will impair its ability to come into compliance. That is a regulator formally acknowledging that the same penalty does not land the same way on every plan.

MACPAC's data shows where the cost actually sits. Of 359 corrective action plans issued across 25 states in one performance year, only 12 carried a financial penalty. KFF finds that when states do fine plans, the amounts are often very small relative to MCO revenues and profits. So for the overwhelming majority of accountability actions, the cost of a CAP is not the fine — it is the remediation labor required to close it, on the state's schedule, while normal operations continue.

Labor is the one input that does scale with the size of the organization. The obligation is flat; the capacity to absorb it is not. That is the whole of it, and every figure in the table above is publicly checkable.

The financial frame

FigureWhat it measures
1% Oregon's monthly administrative performance withhold on adjusted capitation, tied to the 45-day submission and 63-day correction standards.
2% / 2% New Jersey's monthly ceilings on encounter denial rate and duplicate encounter rate, measured separately. Miss either and capitation is withheld until resolved.
98% in 30 days Texas's 835 reconciliation standard against an accepted 837 with an internal control number, including adjustments and voids.
$33.2 million
all categories
Florida liquidated damages across 288 final actions in FY2023–24, spanning all compliance categories rather than encounter data alone, with damages levied against every contracted plan and desk reviews accounting for the majority. Do not read this as Florida's encounter-failure total.
~$2.5 million Kaiser Permanente's 2017 California sanction, in two components: $1,792,500 for failure to submit physician-administered drug data and $742,500 for failure to submit out-of-network encounter data. Not appealed.
286 → 264 Washington HCA's published 2024 Molina encounter data validation audit, initial findings to the revised final after reconsideration.
11,116 → 2,852 One Arizona plan's sanctionable pended encounters, preliminary count to final determination, for the December 2025 quarter — final sanction $51,845. Other published quarters show counts of 980 (ALTCS, June 2025) and 4,505 (ACC, December 2024) resolving to zero. Per-letter citations in the reading list; do not derive a per-encounter rate from the dollar figure, the formula is not visible in the letters.
Excluded from MLR Texas treats liquidated damages as unallowable costs — neither medical expense nor premium payment. A data penalty comes straight out of administrative margin and cannot be recovered as a medical cost.

What the state weighs when it sets a sanction

California publishes the factors it considers when deciding whether a CAP closes, continues, or escalates. They are among the clearest public statements of what regulators look for: the plan’s cooperation with the investigation; whether the plan aggravated or mitigated the injury; the corrective action taken to prevent recurrence; the plan’s financial condition, including whether a sanction would impair its ability to come into compliance; and the financial cost of the service denied, delayed, or modified.

The key factor is recurrence. Correcting the specific finding is only the starting point. What matters is whether the plan can show that the underlying cause has been fixed and that the same failure is unlikely to happen again. California requires monthly status updates with supporting documentation until the CAP is formally closed. A narrative update is not enough.

The sanction itself is often not the largest cost. The larger burden is the remediation required to satisfy the regulator, document the fix, and keep normal operations moving at the same time. A recent Medicare Advantage risk-adjustment matter illustrates the pattern, even though it involved a different program and a different enforcement mechanism: the threatened sanction was an enrollment freeze, while the remediation drove a nine-figure accrual. The dollar amount does not translate to Medicaid encounter data. The lesson does: the visible penalty is often only a fraction of the total cost.

The document request

What an auditor actually asks you for

This is the part plans consistently underestimate. The request is not for your encounter file. It's for everything behind your encounter file — and it arrives with a deadline measured in weeks, covering a service year that closed a long time ago.

A real encounter data validation request

Washington HCA, per its published final audit reports

  1. A random sample of 120 encounters representing 12 claim types — ten per claim type — drawn from a full calendar year of service dates.
  2. For each sampled encounter, the complete original network provider claim, including all header and line-level detail.
  3. The complete adjudicated claim, also with full header and line-level detail.
  4. The claim adjudication information.
  5. The final paid amounts.

HCA's published 2024 Molina EDV final notice states the sample in those terms — 120 encounters, twelve claim types, ten per type, service dates in calendar 2021 — and reduced findings on reconsideration from 286 to 264. Other published HCA EDV reports show the same sample architecture. Source: 2024 MHW EDV Final Notice and Report.

The lesson in those numbers

Findings move. In Arizona, one plan's sanctionable pended encounters went from a preliminary count of 11,116 to a final determination of 2,852 in a single quarter. In other published quarters, preliminary counts of 4,505 and 980 resolved to zero. In Washington, a published 2024 EDV report moved from 286 findings to 264 on reconsideration.

That gap between preliminary and final is not luck. It is the plan producing evidence inside the challenge window — and the plans that produce it are the plans that already had it. Nobody reconstructs a year of claim-to-encounter lineage in thirty days from a standing start.

Which reframes the whole problem. The question is not whether your data is clean. It's whether you can demonstrate it is clean, per encounter, on demand, for a service year that closed eighteen months ago — and whether you can show the remediation trail for the ones that weren't.

HCA may impose sanctions if the Contractor fails to meet one or more of its obligations under this Contract, a CAP, or applicable law, including but not limited to submitting reports, documents, data, or any other information that is inaccurate, incomplete, untruthful, or untimely.

Washington State Health Care Authority managed care contract

Why a clinically excellent plan can still fail. Kaiser Permanente's own stated explanation for its approximately $2.5 million California sanction, quoted in the state's published notice, was that its systems were built for quality, access and integration of care and were never designed or updated to collect information in the format the state required. The failure was not medical, operational, or even about data hygiene. It was that the plan's architecture had no job called "produce state-format encounter data with lineage."

The capability underneath

Reporting tells you what happened. Audit defensibility proves why.

Most plans respond to audit pressure by building better reports. That helps, but only to a point. A report is downstream of the underlying transaction. If the connection between the paid claim and the submitted encounter was not captured at the time, a later report cannot recreate it. And that connection is exactly what an auditor will ask you to prove.

Definition

What audit defensibility actually means

We sometimes call it "audit insurance," but it is not a product or a financial instrument. It is an operating capability: the ability to prove, on demand, what happened to a specific member, claim, or encounter.

That means being able to show who the member was, what eligibility information was available on the date of service, what the claim relied on when it adjudicated, what provider data was used, whether any retroactive change occurred and when, whether the encounter passed state and T-MSIS checks, and what action was taken, by whom, on which record.

Most of this information usually exists somewhere. The issue is whether your team can assemble it quickly, consistently, and in a form that will stand up to review — or whether it takes heroic manual effort under a thirty-day deadline.

Platform

UniSync

A conformance-and-reconciliation layer for managed care operations. It conforms, reconciles and trust-scores operational data across the systems you already run, and it runs alongside production — no core migration, no rip and replace. What it produces is a defensible, point-in-time record of what was received, transformed, submitted, returned, and resolved.

Module

EncounterCURE

Encounter lifecycle management against each state's actual rules. Pends surfaced while the resolution clock is still open. Voids tracked through to resubmission. 837 and 835 reconciliation maintained as a standing state rather than a quarterly scramble. Per-encounter lineage back to the adjudicated claim.

Module

EnrollmentCURE

Daily enrollment processing and 834 reconciliation between the state file and your membership system, with retroactive adds, drops and reinstatements tracked to resolution — including the capitation consequences. Built for the redetermination volume arriving in 2027, not the volume of 2019.

Every deployment is configured to the client's environment — their state contracts, their submission windows, their source systems, their reconciliation rules. There is no generic version of this, because there is no generic state.

What it looks like when the record already exists

Client identity withheld at the client's request. Results drawn from the plan's own audit findings and state sanction determinations. A second proof point will land on this page when it is cleared.

Medicaid plan · published encounter-sanction state

Zero sanctions and clean audit findings two consecutive years — the first time in the plan's history

This plan operates in one of the few states that assesses encounter sanctions quarterly and publishes the results by name. Before the engagement, pended encounters were surfacing after the resolution window had already closed, and the evidence needed to challenge a preliminary finding had to be assembled by hand, per encounter, after the fact.

The change was not a better report. It was making claim-to-encounter lineage a standing property of the data — so a pend is visible while the clock is still running, and the documentation supporting every submitted encounter already exists when the state asks for it.

Delivered on: UniSync, with EncounterCURE and EnrollmentCURE modules configured to the plan's specific state contracts, submission windows and source systems.

Webinar

Surviving the Encounter Data Audit: What Sanction-Free Actually Requires

How state encounter enforcement really escalates, what an auditor's document request looks like in practice, and what sanction-free actually requires of the record.

Surviving the Encounter Data Audit webinar

45 minutes · No cost. Register and you'll get the on-demand recording when available.

What's covered

  • Why an audit you don't control still becomes your evidence problem.
  • The escalation ladder: notice of concern, notice to cure, CAP, sanction — and what stops it at each stage.
  • The real document request a state sends, item by item.
  • What the H.R.1 enrollment changes do to the same data layer in 2027.
  • How to become audit-ready without a huge system overhaul.
  • Prepared Q&A: challenge windows, CAP close-out, and where to start with limited resources.

Presented by CureIS Data and AI Architect, Gabe Madril.

From the CureIS blog

Before Claims AI, Build the Record an Auditor Would Trust

The argument underneath this entire page. Why claims looks like the obvious first AI pilot and is usually the wrong one, the five-question test for picking a safe first move, and what audit defensibility requires operationally — including the seam-by-seam trust-scoring exercise you can run on your own 90-day population.

The muscle memory of evidentiary backing — where a decision came from, what data supported it, and how far you could trust it — is exactly the skill set a successful AI capability is built on. And there's no cheap shortcut to it.

Bret Randolph, Chief Operating Officer, CureIS Healthcare

Readiness self-assessment quiz

Eight questions an auditor will effectively ask you

Instant read-out. Your answers are not collected or stored by us. If most of them are guesses, that's your assessment.

We can trace any submitted encounter back to its adjudicated claim, at header and line level, without anyone assembling it by hand.
Pended encounters surface to someone who can resolve them while the state's resolution window is still open, not after it closes.
We know, per state contract, our exact submission window, correction window, and error threshold — and could recite them without looking.
Every encounter we voided is tracked through to resubmission, and we would notice one that was voided and never came back while the claim still shows as paid.
Our 837 submissions are reconciled against the returned 835s continuously, including adjustments and voids — not at quarter close.
If a state issued preliminary findings on a service year that closed eighteen months ago, we could produce per-encounter evidence inside a thirty-day challenge window.
We keep a time-stamped record of what our eligibility and enrollment data said and when, and could hand it to an auditor this week.
Someone owns encounter and audit readiness by name, and knows what our last data validation audit actually found.
Answer the questions above and your read-out will appear here.

Reading list

The source material

Federal framework, independent research, and the state primary sources behind every figure on this page.

Federal framework

Independent research

State primary sources

Find your own state. Search your state Medicaid agency site for "encounter data validation," "sanctions," or "administrative actions." Agencies that publish do so inconsistently — sometimes under oversight, sometimes under program integrity, sometimes only in the annual managed care report.

Plain English

Glossary

Encounter
The record a plan sends the state for a service it was financially liable for. Not the same thing as the claim it paid — it is a separate submission, in the state's format, inside the state's window, and it is what gets audited.
Pend
An encounter the state accepted into its system but could not fully process, usually because something failed an edit. It sits waiting. Arizona gives plans 120 calendar days from the processing date to clear it.
Void and replace
Withdrawing a submitted encounter and sending a corrected one. The failure mode is voiding without resubmitting, which Arizona explicitly defines as an omission error when the underlying claim still shows as paid.
Encounter data validation (EDV)
The audit itself. The state samples encounters and compares them against the plan's own paid claim file and source documentation, measuring omission, element omission, element surplus, and element accuracy.
Encounter omission error
A service the plan was financially liable for but never submitted — or one it voided and never resubmitted. The most expensive category, because it understates your population.
Corrective action plan (CAP)
A documented remediation plan the state approves and monitors. Not a penalty. By far the most common state response, and the stage where most matters actually end.
Liquidated damages
Contractual, and framed by states as a reasonable estimate of their projected financial loss rather than punishment. New Jersey's are cost-based, set to make the state whole, which is why no fee schedule exists there.
Sanction
The penalty. Civil money penalty, capitation withhold, suspension of new enrollment, permitting enrollees to transfer out, temporary management, or contract termination.
Capitation withhold
The state keeps a slice of what it owes you until you comply. Oregon withholds 1% of adjusted capitation monthly against its submission standards. In New Jersey, withheld amounts eventually become non-recoverable.
T-MSIS
The federal data system states report Medicaid data into. More than 6,000 data quality checks. Compliance actions resumed September 1, 2025, and repeated monthly misses can put the state under a CAP — which the state then pushes down to its plans.
Data lineage
The traceable path from the claim you received, through adjudication, to the encounter you submitted, to what the state returned, to what you did about it. The thing an auditor is actually asking for.
Audit defensibility
The operational ability to prove, on demand, what the plan knew, when it knew it, which system it came from, and what action followed. We sometimes call it audit insurance.

Questions we get asked

Straight answers

What actually triggers a sanction against a Medicaid plan?

Grounds for federal sanctions are listed in 42 CFR 438.700 and include misrepresenting or falsifying information furnished to CMS or the state — a ground that sits in the higher penalty tier under 42 CFR 438.704.

In practice, most Medicaid sanctions are contractual and state-imposed rather than federal. The most common documented triggers are encounter data that is late, incomplete, duplicated, or unresolved after the state flagged it; network adequacy failures; performance measure shortfalls; and untimely provider payment. Arizona's published record shows unresolved pended encounters as its most frequent basis.

What's the difference between a CAP, liquidated damages, and a sanction?

A corrective action plan is a documented remediation plan the state approves and monitors. It is not a penalty, and it is the most common state response by a wide margin. Reviewing 34 states' managed care program annual reports for performance year 2023, MACPAC counted 359 CAPs issued by 25 states — against 106 civil monetary penalties from 11 states and 187 liquidated-damages actions from 10 states. Only 12 of those 359 CAPs carried a financial penalty at all.

Liquidated damages are contractual, and states describe them as reasonable estimates of their projected financial loss rather than punishment. Florida draws that distinction explicitly.

Sanctions are the penalties. One caution when comparing states: MACPAC found at least one state that imposed liquidated damages but did not report them as sanctions, because it did not classify them that way. The categories are not applied consistently.

How long do we actually have to fix a pended encounter?

It depends entirely on the state, and the windows are shorter than most plans assume. Arizona requires all pended encounters resolved within 120 calendar days of the processing date. Oregon requires corrections within 63 days of notification and valid claims submitted within 45 days of adjudication. Tennessee returns rejected batches within two business days. Texas requires 98% of 835 transactions within 30 days of an accepted 837.

The operational problem is rarely the length of the window. It's that the pend often isn't visible to the people who could resolve it until the window has closed.

Can we challenge a preliminary audit finding?

Yes, and the published record shows it works — when you have the evidence. States generally issue preliminary findings, open a challenge window, then issue a final report on which sanctions are assessed. In Washington, HCA's published 2024 Molina EDV report reduced findings on reconsideration from 286 to 264. In Arizona, published quarters show preliminary sanctionable pend counts of 11,116 resolving to 2,852, and counts of 4,505 and 980 resolving to zero.

The constraint is that a challenge window is typically about thirty days and covers a service year that closed long ago. Plans that win these have per-encounter documentation already in hand. Nobody builds it from scratch inside the window.

Our claims data is clean. Why would our encounter data fail?

Because the state isn't auditing whether you paid the claim. It's auditing whether the record you sent the state matches the claim you actually paid, in the state's format, inside the state's window — and then whether you can prove it per encounter.

The failure modes live between systems: an encounter voided and never resubmitted while the claim still shows as paid; a pend resolved in the claims system but never returned to the state; provider or member reference data out of sync; an 837 accepted but its 835 never reconciled. Kaiser Permanente's own stated explanation for its approximately $2.5 million California sanction was that its systems were built for quality, access and integration of care and were never designed to collect information in the format the state required.

How much does a data sanction actually cost?

The fine is usually the smallest number. Both KFF and the National Health Law Program find Medicaid managed care fines are often very small relative to plan revenues.

The larger exposure is elsewhere. Encounter data feeds risk adjustment and capitation rate setting, so understated encounters understate the cost of your population in the rate you're paid for years — Washington's state auditor said plainly that incomplete or inaccurate information could affect premium rate accuracy. Damages can't be passed through: Texas treats them as unallowable costs, excluded from the MLR calculation. In New Jersey, withheld capitation becomes non-recoverable once liquidated.

And remediation dominates. The sharpest illustration comes from a different program: in a 2026 Medicare Advantage risk-adjustment matter, CMS threatened enrollment and marketing sanctions over years of diagnosis corrections submitted outside the required systems. The threatened penalty was an enrollment freeze; the remediation produced a roughly $935 million accrual. Encounter validation works differently, but the ratio holds — the penalty is the visible cost and rarely the largest one.

Does H.R.1 create new encounter data requirements?

No. H.R.1's data provisions are about eligibility verification — addresses and Social Security numbers, Death Master File checks, cross-state duplicate screening, and more frequent redeterminations. Encounter data obligations are separate, older, and enforced through state contracts, T-MSIS reporting, and the federal match.

The connection is operational. Six-month redeterminations for expansion adults, effective for renewals scheduled on or after January 1, 2027, roughly double redetermination volume and therefore the retroactive adds, drops and reinstatements moving through 834 reconciliation and capitation. That's the same enrollment record an auditor will eventually ask you to substantiate, and the same data layer that feeds encounters. The H.R.1 resource center covers that side in full.

We have limited resources. Where's the most leverage?

Lineage on one thing, rather than a plan-wide assessment. Pick a single state contract and a single claim type, and establish whether you can trace every submitted encounter back to its adjudicated claim, and every pend to its resolution, without anyone assembling it by hand.

If you can't, that's the finding — and it's more useful than a hundred-page readiness report, because it's the exact thing the audit will test.

Should we build this ourselves or bring in help?

It depends on your IT capacity and your runway. Continuous reconciliation and per-encounter lineage are real engineering work but entirely solvable, and plans with strong internal teams have built them. The catch is that a prototype answers the easy question — can we generate something useful from clean data — while production has to answer the hard one: can we generate something accurate, repeatable, traceable, and defensible from the data we actually run on, across delayed feeds, manual adjustments, retroactive changes, and rules that live in people's heads.

Either way the requirement is the same: conformed data, continuous reconciliation, and an audit trail.

What's the first step if we think we're exposed?

Take a recent 90-day population and ask four questions. How often did eligibility on the date of service disagree with the claim? How often did retroactive changes land after payment? How often did encounters fail for knowable reasons? And how much manual effort did reconstruction take?

That's your baseline, and it's four answers rather than a project. Then find out when your last data validation audit was and what it actually found — a surprising number of plans don't know.

One move you can make this week

Find out whether you could trace one encounter end to end

Pick a single state contract and a single claim type. If producing the original claim, the adjudicated claim, the adjudication detail, and the final paid amount takes a person more than a few minutes, that's your starting line — because that is the actual document request.

Not sure where to start? Sit down with us. One of our analysts will walk your claim-to-encounter path end to end and show you exactly where you stand. No commitment, and a real person, not a bot.

CureIS has spent nearly two decades inside managed care data and claims operations, running daily enrollment processing and encounter operations for leading health plans and systems in Arizona, California and elsewhere. Our EncounterCURE and EnrollmentCURE modules handle the encounter lifecycle and daily enrollment processing, and UniSync continuously conforms, reconciles and trust-scores the data underneath. CureIS tools work alongside the core systems you already run, including Facets, QNXT and HealthRules. No rip and replace. Implementation in weeks.