Est.

Medicaid Managed Care Audit and Reporting Obligations for SNFs

Medicaid managed care shifts financial risk to SNFs, triggering heightened audit scrutiny.

Senior Writer · · 12 min read
Cover illustration for “Medicaid Managed Care Audit and Reporting Obligations for SNFs”
Compliance Ops · September 30, 2026 · 12 min read · 2,699 words

Medicaid managed care changes who a skilled nursing facility answers to, and it changes the structure of financial risk that underlies every claim submitted, shifting exposure in ways the traditional model did not. Under the traditional fee-for-service model, the state agency pays the SNF directly, and the financial exposure for miscalculated rates or utilization overruns rests with state and federal government. Managed care flips that arrangement: the state contracts with managed care organizations and hands them the financial risk, which builds an incentive structure that can push MCOs toward tighter utilization controls and, in some cases, toward denials. That single structural shift is the reason the rest of this piece exists.

In 2026 alone, CMS withheld $1.3 billion in Medicaid funding from California and deferred nearly $260 million in payments to Minnesota over unsupported or potentially fraudulent claims, with scrutiny expanding to other states including New York and Hawaii. The other points toward the MCO, governed by a private contract that layers its own requirements on top: prior authorization protocols, documentation standards, appeal timelines, encounter data submissions, none of which existed in a pure fee-for-service relationship. Recent legislative activity adds another layer of friction. The Working Families Tax Cut legislation, signed July 4, 2025, changed how state directed payments are handled under 42 CFR § 438.6(c)(2)(iii), which complicates how managed care rates get set and how payments eventually reach the SNF OIG Data Brief June 2026.

CMS reinforced the oversight architecture behind all this in an Informational Bulletin, which restates that states must monitor MCO compliance across 14 distinct program areas under 42 CFR § 438.66(b), covering claims management, finance, and quality, and must use the data they collect to actually improve MCO performance under 42 CFR § 438.66(c) OIG Data Brief June 2026. SNFs sit downstream of that entire chain. Whatever a state finds wanting in an MCO's claims processing or quality metrics can, eventually, trace back to how a facility documented and billed a resident's stay. Knowing who is watching whom, and where the SNF sits in that oversight chain, is the starting point for managing audit risk with any precision.

The current enforcement climate: what federal agencies are actively pursuing in 2026

The dollar figures involved in 2026 enforcement actions give a sense of scale that's hard to ignore. CMS withheld $1.3 billion in Medicaid funding from California and deferred nearly $260 million in payments to Minnesota over claims regulators found unsupported or potentially fraudulent, and that scrutiny has since expanded to New York and Hawaii. They reflect a federal posture that treats Medicaid managed care billing accuracy as a front-line concern rather than a background administrative matter.

Corporate Integrity Agreements remain OIG's sharpest enforcement tool. A CIA doesn't just settle a case, it converts a facility from a routine compliance actor into a subject of sustained, granular oversight, with monitoring obligations that can run for years. OIG's active audit series W-00-24-31535, announced February 8, 2024 and last modified August 13, 2026, is examining whether Medicaid MCOs complied with federal requirements when denying access to services requiring prior authorization, specifically medical and dental services, behavioral health services, and associated drug prescriptions. SNF admissions aren't named in that particular scope, which matters: it tells facilities that this specific audit thread isn't aimed at them directly, even as adjacent enforcement clearly is.

November 2024 brought the first nursing-facility-specific compliance guidance OIG has issued since it updated its general compliance guidance a year earlier, signaling that OIG now treats nursing facilities as a distinct compliance category worth its own document, rather than folding them into general provider guidance OIG Data Brief June 2026. That's not a small bureaucratic footnote. Because a documentation gap or a billing compliance failure isn't necessarily contained to a billing dispute, this reframing matters enormously for SNFs. It can escalate, under the right facts, into a fraud allegation. OIG currently has 13 active workplans targeted for nursing homes, some active since 2023 and continuing into 2025–2026. OIG, CMS, and DOJ are working in a concerted effort in which bills for grossly substandard care can be treated as fraudulent because care is deemed not to have been provided, so a billing compliance failure can escalate into a fraud allegation.

Prior authorization documentation: the highest-frequency SNF audit flashpoint in managed care

Prior authorization is where Medicaid managed care audit risk concentrates for SNFs. That spread is itself a compliance signal. When two MAOs reviewing similar populations land 20-some points apart on denial rates, something other than clinical variation is likely driving the gap https://oig.hhs.gov/reports/all/2024/some-selected-skilled-nursing-facilities-did-not-comply-with-medicare-requirements-for-reporting-related-party-costs/.

The appeal data sharpens the picture further. Enrollees and providers appealed 18 percent of SNF denials, and MAOs overturned 95 percent of those appeals in the enrollee's favor OIG Data Brief June 2026. A 95 percent overturn rate raises an obvious question: were the initial denials ever medically sound to begin with, or is the documentation simply not built to survive the review it should have passed the first time OIG Data Brief June 2026? OIG itself flagged this as a validity concern for the underlying denials OIG Data Brief June 2026.

MAOs overturned 97 percent of naviHealth's denials on appeal OIG Data Brief June 2026. That discrepancy is not marginal; it forms a pattern to track facility by facility and contractor by contractor.

Residents already living in a nursing home face a starker gap still. MAOs and their contractors denied SNF-level care requests from existing nursing home residents 40 percent of the time, compared to just 11 percent for all other enrollees OIG Data Brief June 2026. For long-stay facilities, that nearly fourfold disparity carries real financial weight, and it should shape how those facilities build their documentation strategy for continuing-stay residents specifically.

CMS has responded with a Medicare Advantage prior authorization data collection pilot, with its first data collection expected in late 2026, gathering service-level data that includes third-party vendor involvement. Affected payers must also now issue prior authorization decisions within 72 hours for expedited requests and seven calendar days for standard requests, starting in 2026.

What does this mean operationally for an SNF compliance program? Medical necessity documentation needs to be built to survive two separate reviewers, the MAO's own initial review and, where applicable, a distinct third-party contractor review, each of which may apply a different threshold for approval. Therapy progress notes and skilled nursing documentation need to be individualized and clinically specific rather than boilerplate, since generic language is consistently the weakest point in a denial dispute. Facilities that decline to appeal denials risk more than lost revenue, they risk creating a pattern that looks, from the outside, like tacit acceptance of inappropriate denials. Tracking denial and overturn rates by MCO and by contractor is the most direct way to catch an anomalous pattern before it becomes a systemic problem.

MCO contract compliance obligations that SNFs often underestimate

An MCO contract reads, on its surface, like a revenue agreement. A facility that treats it that way misses what it actually is: an enforceable compliance instrument, carrying its own documentation formats, encounter data submission standards, appeal response timelines, credentialing requirements, and network participation terms. None of these obligations are optional add-ons to the federal and state regulatory framework, they sit alongside it.

Network adequacy is a good example of how this expands over time. Effective in 2025, CMS External Quality Review protocols require states running Medicaid managed care programs to conduct and report network adequacy validation. CMS tightened the underlying network adequacy rules further in 2024, with a general effective date of July 9, 2024, and staggered applicability dates that stretch out through 2028. SNFs that participate in-network under these contracts inherit documentation and performance obligations tied directly to those validation requirements, whether or not the facility fully appreciates that connection at the time it signs the contract.

Encounter data is where facility-level errors travel furthest upward. An SNF that submits inaccurate or incomplete encounter data isn't just creating a paperwork problem for itself, it's introducing noise into the state's broader compliance picture, and that noise can trigger a targeted review back down at the facility level.

State directed payments add yet another moving part. The Working Families Tax Cut legislation directed CMS to revise the total payment rate limit for SDPs covering inpatient hospital services, outpatient hospital services, nursing facility services, and qualified practitioner services at academic medical centers. SNFs receiving supplemental or directed payments through MCO contracts need to track how these changes ripple into their own payment and reporting obligations, because the rate limit isn't static.

State-level variation compounds all of this. Florida's Statewide Medicaid Managed Care program, effective February 1, 2025, reshaped contracts, quality standards, and billing requirements across the state. A facility operating across multiple states can't rely on a single federal compliance framework, it needs a state-specific contract compliance matrix for each jurisdiction where it operates. On top of that, CMS refined its Managed Care Program Annual Report questions on February 19, 2026, to better capture enrollment for risk-based programs and to remove content now duplicated in the MLR Summary Report and NAAAR. SNFs should understand how their MCO partners report on them within that framework, since MCO-level findings can, and do, trigger facility-level scrutiny.

Cost reporting accuracy: where Medicaid managed care obligations intersect with Medicare cost report compliance

Cost reports do more than satisfy a filing requirement. An error in one facility's cost report doesn't just affect that facility, it introduces distortion into a rate-setting methodology that other facilities depend on.

The scale of what's at stake here is considerable. OIG's audit A-07-21-02836, completed December 18, 2024, examined SNFs with Medicare cost reporting periods ending across FYs 2015 through 2020, a period in which SNFs reported receiving $160.4 billion in Medicare payments and paying $65.4 billion to related parties. Related-party transactions at that magnitude are, unsurprisingly, a high-priority scrutiny area.

CMS's implementation status, as of July 1, 2026, is mixed. One recommendation remains open: requiring MACs to fold related-party cost review into their normal desk review or audit process. Until that happens, oversight of these disclosures will stay inconsistent from one contractor to the next.

Medicaid cost report filing runs on its own timeline, due within 5 months after a provider's fiscal year end, using CMS 2540 cost reporting schedules along with state-specific supplemental schedules. North Carolina's Medicaid SNF cost report for fiscal years ending on or after September 30, 2025, for instance, uses Version 6.02 for non-hospital-based facilities and Version 6.04 for hospital-based ones, a detail that illustrates a broader truth: states update their cost reporting requirements on their own schedules, entirely independent of the federal cycle. Medicaid SNF reimbursement itself is set at the state level and varies from state to state, and in a managed care environment, the cost report may need to separate encounter data and managed care revenue from fee-for-service revenue. Facilities that blend these categories improperly create audit exposure at both the state and federal level simultaneously. With CMS's related-party guidance now published, facilities have lost the ability to claim they lacked direction, and MAC enforcement, uneven as it may still be, is expected to tighten. Cost reports are foundational, providing CMS with transparency about SNF costs and supplying the data CMS uses to update payment rates, meaning errors here affect not just the individual facility but the rate-setting methodology across the sector. Of 14 SNFs in the sample, 7 did not properly adjust related-party costs to Medicare-allowable levels, resulting in more than $1.7 million in overstated costs, and 3 did not properly disclose related parties at all. CMS developed and issued guidance on appropriate methods for SNFs to determine allowable related-party costs (42 CFR § 413.17), and the recommendation is closed/implemented. CMS issued guidance to reeducate Medicare Administrative Contractors on reviewing, granting, and documenting SNF requests for exceptions to cost reporting requirements under 42 CFR § 413.17(d), and the recommendation is closed/implemented.

Billing compliance under PDPM and consolidated billing: the audit targets embedded in the 2026 payment rule

The FY 2026 SNF PPS Proposed Rule updates payment rates under the Patient-Driven Payment Model, adjusts the Value-Based Purchasing program, and changes elements of the Quality Reporting Program. Each of those updates changes, in some way, how a facility needs to code, document, and bill a resident's stay. The rule isn't just a rate adjustment, it's a fresh set of documentation demands layered on top of existing ones.

These aren't hypothetical risks conjured for a compliance memo, they are the named subjects of open federal audit activity. Supplemental Medicaid payments sit inside that same workplan as a financial focus area, and SNFs receiving them need to document the basis for each payment and make sure it's captured correctly in both billing and cost reporting.

Medicare Part B billing during a Part A stay is a persistent trouble spot even outside managed care, and OIG's workplan keeps it as an active financial focus. Managed care adds a wrinkle here that fee-for-service never had: MAO coverage rules for Part B services rendered during a Part A stay can differ from original Medicare's rules. A facility applying fee-for-service logic to a managed care resident can get the billing wrong without realizing it. Part D medication responsibility during Part A stays carries the same kind of risk. It's named in OIG's workplan as a financial focus area, and facilities that shift this cost incorrectly generate both a billing error and, depending on intent, potential fraud exposure.

One notable signal buried in the FY 2026 proposed rule: a Request for Information under Executive Order 14192, seeking input on streamlining Medicare regulations. That's not a new rule, but a request for comment, and it shouldn't be read as a green light to loosen compliance infrastructure in anticipation of relief that hasn't actually materialized. The most practical defense against PDPM and consolidated billing errors remains pre-bill claim review and internal auditing, catching a mismatch between clinical documentation and billing codes before the claim goes out the door is considerably cheaper than untangling it after a post-payment audit. OIG is actively auditing SNFs for PDPM upcoding, lack of medical necessity documentation, improper therapy billing, and billing errors under SNF Consolidated Billing, which are not speculative risks but named OIG workplan targets.

The OIG compliance program framework and its mapping to managed care audit risk in nursing facilities

November 2024's Nursing Facility Industry Segment Specific Program Guidance is the first industry-specific document OIG has issued since it updated its General Compliance Program Guidance in November 2023. It isn't mandatory in itself, but the Requirements of Participation, which are mandatory for Medicare and Medicaid reimbursement, are modeled on OIG's compliance guidelines. So the guidance functions as something closer to a de facto standard than its non-binding label suggests.

The ROPs build around seven compliance program elements: compliance policies and procedures paired with a designated Compliance Officer, staff training and education, auditing and monitoring, reassessment and modification in response to identified weaknesses, addressing quality-of-care issues through accurate care planning, preventing abuse and neglect, and enforcing disciplinary mechanisms for violations.

How do these seven elements actually map onto managed care audit risk? Auditing and monitoring can't stop at billing codes anymore, it has to encompass prior authorization denial tracking, encounter data accuracy, MCO contract terms, and related-party cost disclosures. Reassessment needs to keep pace with a regulatory environment that moves faster than most compliance calendars expect, MCPAR revisions, phased network adequacy effective dates, state-level Medicaid bulletins arriving on their own schedules. And training deserves particular attention, because staff handling prior authorization requests need to understand what documentation standards drive overturn outcomes. The fact that 95 percent of appealed SNF denials get overturned suggests the deciding variable, in most cases, is documentation quality rather than the underlying medical necessity itself.

None of this guidance emerged in a vacuum. It reflects input drawn from enforcement actions, CIA monitoring, investigations, and stakeholder engagement. It isn't aspirational language, it describes the standard facilities are already being measured against. An effective compliance program demonstrably reduces the likelihood of a CIA, and the seven-element framework is the documented evidence of that program.

HUD Section 232 and the audit layer that applies when a SNF carries government-insured financing

Section 232 financing adds one more layer entirely.

Filed underCompliance Ops

More in Compliance Ops