Governance is not optional
Every model, every algorithm, every AI-generated finding must be explainable. CMS requires it. Providers have due process rights. When a payment is suspended based on an ML score or an LLM’s assessment of clinical documentation, the state has to explain why — clearly and with evidence. Opaque scores do not survive legal challenge.
The same principle applies to operational decisions. Technology should not automate inefficient processes or inconsistent policies. Before implementing advanced analytics or AI, states should evaluate whether underlying workflows, escalation paths and review processes are designed for the outcome they want to achieve. Modernizing technology without modernizing operations simply accelerates existing inefficiencies.
Cross-agency collaboration expands what any single entity can see. Medicaid fraud intersects with Medicaid Fraud Control Units, state licensing boards, CMS’s Unified Program Integrity Contractors (UPICs) and the Office of Inspector General. Platforms need to support secure data sharing while staying within HIPAA, 42 CFR Part 2 and state privacy law.
And here is one that program leaders often underestimate: managed care encounter data. MCOs process the majority of Medicaid volume in most states. If your managed care contracts do not mandate timely, standardized encounter submission, your program integrity operation is working with less than half the picture.
Governance also requires balancing integrity objectives with access to care. States are understandably cautious about introducing new prepayment controls that could delay services, create provider friction or generate political scrutiny. The goal is not to slow legitimate claims processing. It is to apply intelligent risk-based review that protects taxpayer dollars while confirming beneficiaries continue receiving timely care and providers are paid promptly for appropriate services.
What I have seen work — and what has not
A few patterns show up consistently in programs that deliver real results:
Start with data quality. Poor data quality leads to false positives, which means investigator fatigue, which means real fraud gets buried in noise. Invest in provider enrollment validation as a front-door defense — screen thoroughly before providers enter the program so you spend less effort catching them after.
Just as important, invest in the people using the system. The strongest program integrity organizations treat workforce development as a core component of modernization. Investigators, clinicians, data analysts and program integrity leaders need new skills to effectively interpret risk scores, validate findings and continuously improve detection approaches. Sustainable results come from building workforce capability alongside technology capability.
Deploy rules for what you know. Reserve ML for discovering what you do not. Build feedback loops so investigation outcomes improve model accuracy over time. This is not a one-time implementation — it is a living system.
The most successful programs also take an incremental approach. Rather than attempting enterprise-wide transformation all at once, they focus on targeted use cases, demonstrate measurable value and expand capabilities over time. This modular strategy aligns well with CMS certification expectations, state funding cycles and the realities of organizational change.
Engage clinical staff and policy professionals from day one. The best fraud detection reflects deep program knowledge. A data scientist who does not understand how home and community-based services waiver services are authorized will build models that flag legitimate claims and miss actual fraud.
And do not underestimate change management. Program integrity is an organizational capability, not a procurement. The technology only works when investigators trust it, policy staff inform it and leadership funds it sustainably.
Where this is headed
The direction is clear. We are moving from periodic audits toward continuous, intelligent prevention. Real-time streaming catches problems at the moment of submission. AI reads documentation the way a clinical reviewer would — but across every claim, not just the ones someone manually selects. Federated approaches let states learn from each other’s patterns without sharing protected data.
The CMS interoperability framework announced in July 2025, with over 60 organizations signed on, signals that the infrastructure for connected, real-time health data exchange is becoming standard rather than aspirational. States that align their technology investments with MITA 3.0 maturity principles and pursue enhanced FFP for modular, certified systems will be positioned to act on these capabilities as they mature.
The path forward is unlikely to be a single large-scale transformation initiative. More often, progress will come through modular and agile modernization efforts that advance programs incrementally through the four maturity levels. States that can demonstrate measurable improvements in payment accuracy, investigative efficiency and provider experience will be better positioned to sustain funding and continue scaling capabilities over time.
The math is straightforward, but the value extends beyond avoided losses. Effective program integrity improves public trust, reduces administrative burden on providers, allows investigators to focus on the highest-risk cases and helps confirm limited Medicaid dollars are directed toward individuals and families who need services most.
The question for Medicaid leadership is not whether to modernize FWA detection, but how quickly they can move from reactive investigation to proactive prevention — how fast we move from talking about it to building it.