Original briefings. Zero spin.
Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.
CMS Gives States 30 Days to Justify Every Medicaid Provider After Watchdog Found 10% of Plans Reported Zero Fraud Cases

Medicaid managed care plans covering 1.6 million people and $8 billion in annual payments referred exactly zero fraud cases to investigators in 2022, according to a Department of Health and Human Services Office of Inspector General report published in September 2025. That's 10% of all plans reviewed. Not slow. Not thin. Zero.
CMS Administrator Mehmet Oz is now moving on it. Speaking at Politico's Public Health Care Summit, Oz announced that all 50 states have 30 days to submit plans showing how they'll revalidate Medicaid providers, according to GovCIO Media & Research. States must identify areas at "high risk" for waste, fraud and abuse and prove the providers billing Medicaid actually exist.
Oz gave a blunt example. One state had roughly 5,000 people billing as providers. Several hundred couldn't be reached to confirm basic facts: who they are, whether their Social Security number checks out, whether they're licensed to provide the service at all. "Isn't that the basic thing you would want to do if you actually care about the program," Oz said, according to GovCIO.
This is not the administration's first swing. In February, CMS and the White House rolled out what they called a "major crackdown" on Medicare and Medicaid fraud, including a nationwide enrollment moratorium on certain durable medical equipment suppliers. The 30-day revalidation order is the next phase.
The Math Nobody Can Ignore
The OIG report didn't just find an absence of referrals. It found a referral rate that doesn't square with known fraud levels anywhere else in American healthcare.
The National Health Care Anti-Fraud Association estimates fraud costs the U.S. healthcare system between 3% and 10% of total spending. Apply even the low end to that $8 billion in payments from zero-referral plans, and you're looking at roughly $240 million in potential fraudulent claims that nobody flagged, according to analysis published by WCH Service Bureau.
Among plans that did make referrals, more than half reported two or fewer per 10,000 enrollees in 2022, per the OIG data cited by WCH Service Bureau. That represents a system that isn't looking.
Why the System Doesn't Look
The OIG report points to a structural problem, not just laziness. Only half of Medicaid managed care plans received state or Medicaid Fraud Control Unit training on how to make referrals in the first place, according to WCH Service Bureau's review of the findings. Plans that got trained referred more fraud. Plans that didn't, referred less. That's a fixable gap, not a mystery.
The deeper problem is money. When a state recovers improper Medicaid payments, those recovered dollars go back to the state and federal government, not to the managed care plan that flagged the fraud. Plans eat the cost of running fraud detection units and get none of the recovery upside. Economists call that a negative externality. In plain English, the plans have little financial reason to spend money catching fraud they'll never be credited for stopping.
Staffing makes it worse. Roughly 78% of plans reported their fraud-referral staff split time across Medicaid, Medicare Advantage and commercial insurance lines, according to the OIG data. Medicaid is the lowest-margin, most administratively tangled of the three. Split attention lands there last.
Home Health Is Ground Zero
Separate analysis from Healthcare Markets & Technology, published in February 2026, zeroed in on why home health care is the biggest exposure point in the whole system. It's the single highest-spending taxonomy in HHS's new Medicaid provider spending dataset, north of $288 billion, and carries the highest fraud density per dollar of any category, according to the newsletter's review of the data.
Why home health specifically? There's no clinical artifact to check against, unlike a hospital claim with imaging or lab results attached. Documentation is often self-attested. Caregiver identity is nearly impossible to verify at scale. And the federal matching-rate structure gives states weak financial incentive to police it aggressively, according to the same analysis.
What's Actually New Here
None of the underlying fraud numbers are new. What's new is CMS putting a hard 30-day clock on states and demanding they show their work on provider verification, not just promise to try harder.
Oz did not say whether states will get extra federal money or staff to conduct the reevaluations, according to GovCIO. That's the open question critics on the state administrative side are likely to raise first: audits cost money and manpower, and an unfunded mandate with a 30-day deadline is a very different thing from a funded one.
There's a fair counterpoint here too. State Medicaid agencies have argued for years that they're already stretched managing enrollment, eligibility redeterminations and rate negotiations, and that a hard federal deadline without new resources risks becoming a paperwork exercise rather than a real crackdown. Oz has said he doesn't expect the audits to slow down or eliminate core Medicaid services, but he hasn't detailed what happens to a state that misses the 30-day window or flags a high-risk area it can't afford to fix.
No state has yet publicly submitted a revalidation plan, and CMS hasn't said what it will do if states come back short-staffed or short on answers.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.