XBluesky

House Committee Report on Fraud Against Medicare and Medicaid: Oversight Done Wrong

On September 29, exactly five weeks before the mid-term elections, Republicans on the House Energy & Commerce Committee released a Majority Staff Report on fraud against Medicare and Medicaid. The same day the Committee’s Chairman announced a package of 14 bills, 13 of which would amend the Medicaid statute to address fraud against the program. At this late date, it seems highly unlikely that these bills will find their way to the President’s desk for signature before the end of this Congress. The Majority Staff Report, however, is a final product worth examining.

The report characterizes itself as a “comprehensive” investigation of fraud against Medicare and Medicaid (p. 6). In fact, it focuses largely on Medicaid programs in Democratic-led states. The findings of the report are based on “over 100,000 pages of documents and information” and three Subcommittee hearings. The documents and information produced in response to letters sent to 11 states: California, Colorado, Massachusetts, Maine, Minnesota, Nebraska, New York, Oregon, Pennsylvania, Vermont, and Washington. All but two of these states have Democratic governors. One of the Subcommittee hearings involved four state Medicaid directors, three of which were from states with Democratic governors (California, Minnesota, and New York). 

So, it is hardly surprising that in the section of the report titled “Deficiencies in State Medicaid Program Integrity,” the only examples provided are from Democratic-led states: New York, California, and Oregon (“Insufficiency of Provider Risk Assessments”) and Minnesota, Colorado, Maine, and California (“Utilization of Audits”). Bad actors have demonstrably committed fraud against the Medicaid programs in each of these states. But does the Majority Staff actually believe that their investigation is “comprehensive”? That there are no “Deficiencies in State Medicaid Program Integrity” in Florida or Ohio or any of the other 24 states with Republican governors?

The report states that “The Committee picked a sample of states after looking at a variety of publicly available reports and data…recent cases of Medicaid fraud occurring in certain services…and recent audits and reports that identified certain Medicaid programs of concern.” (p. 30). In selecting the sample, the Majority Staff apparently overlooked the publicly available data in the 2026 National Health Care Fraud Takedown released by the Department of Justice in June. The “Takedown” includes cases alleging fraud against Medicaid programs filed in federal or state court in 42 states: Alaska, Arizona, Arkansas, California, Colorado, Connecticut, Delaware, Florida, Georgia, Illinois, Iowa, Kansas, Kentucky, Louisiana, Maryland, Massachusetts, Michigan, Minnesota, Mississippi, Missouri, Montana, Nebraska, Nevada, New Hampshire, New Jersey, New Mexico, New York, North Carolina, Ohio, Oklahoma, Oregon, Pennsylvania, Rhode Island, South Carolina, Tennessee, Texas, Utah, Vermont, Virginia, Washington, West Virginia, and Wisconsin. The most coherent explanation for the sample selected by the Majority Staff is partisan targeting. 

Along the same partisan lines, the report credits—without qualification—the Trump Administration with having “uncovered $96.4 billion in fraud, stopped $46.2 billion of fraud, and recovered $33.1 billion of fraud through enforcement actions since January 2025” in HHS programs. These are the unsourced, unexplained, and unverifiable numbers posted on the White House Fraud Ledger. There’s no indication that the Majority Staff did its due diligence to assess the accuracy of at least the Medicare and Medicaid components of these figures.

Despite its partisan targeting, the Report does manage to get a few things right. It characterizes fraud against Medicare and Medicaid as a “serious” problem but doesn’t make up numbers of amounts lost to fraud. Instead, it states correctly that “no precise estimate of annual fraud rates in Medicare or Medicaid exists…”(p. 11). It also acknowledges that improper payments are not a measure of fraud: “…improper payments only capture some fraud and also include payment errors, insufficient documentation, or administrative processing failures.” (p. 11)

The Report also provides one piece of new information: the risk levels assigned by the 11 states targeted by the investigation to providers of four different services (Adult Day Care, Applied Behavioral Analysis, Non-Emergency Medical Transportation, and Personal Care Services) that the Report identifies as presenting a high risk of fraud. (Table 1, p. 56). 

By way of background, anti-fraud provisions enacted in the ACA in 2010 require that state Medicaid agencies screen providers before allowing them to enroll in the program and bill for services. The extent of the screening, ranging from database checks to site visits to fingerprinting and criminal background checks, depends on the provider’s risk level; the higher the risk level, the more extensive the screening. Under Centers for Medicare & Medicaid Services (CMS) regulations, states must assign providers one of three risk levels: limited, moderate, or high. For services covered only by Medicaid, and not also by Medicare, each state makes its own determination of risk. The four services highlighted in the report are Medicaid-only services, three of which (ADC, ABA, and PCS) CMS considers “the biggest risks to the Medicaid program.”

The report finds that two of the states—Minnesota and New York—classified all four service types as “high” risk, which would subject providers to the most extensive screening at initial enrollment and upon revalidation. Five of the states—California, Massachusetts, Oregon, Pennsylvania, and New York—classified all four service types as “limited” risk. The remaining four states applied a mix of levels to the four service types. Each of the service types had at least one state classifying it as “limited” risk and one state classifying it as “high” risk. Three of the service types—ABA, ADC, and NEMT—were designated as “limited” risk by a majority of the targeted states. 

Even allowing for state-to-state variation, these data raise some interesting questions. What criteria and what claims data did the 11 targeted states use in determining their classifications? How do the states not targeted by the investigation classify these services, and how did they arrive at their risk levels? Are the patterns similar to those observed with the 11 targeted states? If most states consider ADC and ABA services to present “limited” risk to their Medicaid programs, why does CMS consider those services two of the three “biggest risks”?

Here is where the report’s partisanship degrades its ability to inform. The Majority Staff’s conclusion from the data it presents is not to explore the questions the data raise but to criticize many of the targeted states for not applying an “enhanced risk designation, despite recent patterns of fraud within these programs, including in these states.” (p. 56). The report then launches into an attack on New York for “not complying with federal law by designating provider risk levels” (p. 57) and on California and Oregon for “doing the bare minimum to comply with federal requirements” (p. 58). 

It is altogether appropriate for the Majority Staff to ask whether states are complying with federal requirements for provider screening. It is rank partisanship to ask those questions of only a subset of states, the overwhelming majority of which are led by Democratic Governors. And it is thoroughly inappropriate to take two of those Democratic-led states to task for “doing the bare minimum” to comply with federal regulations—compliance is, after all, what is required, and that is what the report acknowledges they are doing. States may choose to go above and beyond, and perhaps some have; the sample size is too small to know. But no state is required to do so. If the Majority Staff believes that the current federal regulations on provider screening are too lax, it should recommend that CMS Administrator Dr. Mehmet Oz revise them, not call out two of its partisan targets for not doing more than what is required. 

Oversight is an important responsibility that Congress should take seriously. When done right, Congressional oversight has the potential to improve the operation of federal programs by identifying problems and holding federal (and in the case of Medicaid, state agencies) accountable for addressing them. Medicaid is a hugely important program for tens of millions of children and families as well as individuals with disabilities and low-income elderly. Fraud against Medicaid is a major challenge and one that CMS and state Medicaid agencies should work together to address. The program and its enrollees would benefit from a bipartisan, fact-based investigation that is actually comprehensive and gathers and analyzes data from all states, not just a partisan subset. Regrettably, this Majority Staff Report is not that investigation.