← Back to blog

Pass U.S. Medicaid Compliance Reporting: The Exact Evidence CMS Wants

October 1, 2026
Pass U.S. Medicaid Compliance Reporting: The Exact Evidence CMS Wants

Medicaid compliance reporting centres on MDCT-MCR submissions, which cover MCPAR, the MLR summary and NAAAR, alongside timely, auditable Form CMS-64 entries. If you manage a state Medicaid programme or a managed care plan, your first move today is to confirm your team's access to the MDCT-MCR evidence repository and pull the documentation behind one recent submission.


TL;DR:

  • Ensuring timely access and correct documentation in the MDCT-MCR repository is crucial, as missing evidence can invalidate a submission regardless of data accuracy.
  • Managed care contracts require documented evidence of key compliance elements, like a designated officer and regular training, with proof readily accessible during audits.
  • States sampled by PERM must prepare in advance with standard record packages and secure electronic submission channels to avoid automatic improper payment findings.
  • Accurate reconciliation between recovery cases and CMS-64 reports is critical, as unresolved gaps or delays can lead to late or incomplete quarterly expenditure submissions.
  • Building integrated, traceable evidence workflows and maintaining detailed audit trails reduces the risk of governance failures that often trigger Medicaid audit findings.

Keystoneconsulting
Make Compliance Evidence Audit Ready
Keystone integrates with teams to strengthen governance, map workflows, and support traceable reporting for complex compliance delivery.
Explore Keystone Consulting

Table of Contents

CMS managed care reporting streams and the MDCT-MCR portal

Three reporting streams sit at the centre of managed care oversight, and each has its own owner, deadline and evidence trail.

MCPAR, the Managed Care Program Annual Report, must reach CMS within about six months after the close of each contract year, a timing rule set out in Medicaid and CHIP managed care reporting. It covers plan performance across areas such as network adequacy, grievances and appeals, and program integrity activity. The MLR summary works differently: it applies to rating periods beginning on or after July 1, 2017, and has moved onto the MDCT-MCR portal alongside MCPAR for recent submission cycles. NAAAR, the network adequacy and access assessment report, rounds out the trio and is being phased into MDCT-MCR through a series of transition dates running into 2026.

The portal itself, MDCT-MCR, is CMS's web-based system for collecting all three templates, which means a single access failure or a missed password rotation can jeopardise several deadlines at once.

Before your next submission window, confirm the following:

  • Named owner: one person accountable for each report, not a shared inbox.
  • Calendar entry: the exact due date calculated from your contract year end, not a generic annual date.
  • Evidence folder: the source documents (network files, grievance logs, MLR worksheets) linked to the submission record, not held separately.
  • Portal access check: login credentials and permissions confirmed at least thirty days ahead of each deadline.

Treat the MDCT-MCR repository as the single place a reviewer would look first. If the underlying evidence is not attached there, the submission is incomplete no matter how accurate the numbers are.

Minimum compliance programme elements under federal managed care rules

Every managed care contract must build in the compliance programme elements described in managed care compliance toolkit and monitoring guidance, and these elements are what CMS and state contract monitors check first during any review. The minimum set includes:

  • Written policies and procedures that describe how the compliance programme actually functions, not a generic template.
  • A designated compliance officer (CO) with a defined reporting line, separate from operational management.
  • A regulatory compliance committee (RCC) that meets on a set schedule and keeps minutes.
  • Effective training and education delivered to relevant staff on a documented cycle.
  • Effective lines of communication, including a way for staff to report concerns without fear of retaliation.
  • Enforced disciplinary standards applied consistently when violations occur.
  • Ongoing monitoring and auditing, including risk-based work plans and data mining.

Contract language is what turns these into enforceable obligations rather than good intentions: a state's contract with a managed care plan typically references 42 CFR §438.608 directly, so a plan that cannot produce evidence of each element is in breach of contract, not just falling short of best practice.

The evidence CMS expects is specific. A compliance officer's job description showing direct reporting authority, RCC meeting minutes with attendance and action items, training completion logs tied to named staff, and a monitoring work plan showing what was reviewed and when, are the artefacts a reviewer will ask for.

Pro Tip: Keep your RCC minutes and training logs in the same repository as your MCPAR evidence, so a single audit request pulls both without a second search.

PERM and what happens if your state is sampled

PERM, the Payment Error Rate Measurement programme described in PERM: payment error rate measurement, measures improper payments across fee-for-service, managed care and eligibility determinations. It is not a fraud rate: an improper payment can result from a documentation gap or a coding error just as easily as from intentional wrongdoing, and CMS treats measurement and investigation as separate functions, a distinction Georgetown's Center for Children and Families also draws.

PERM measurement and investigation paths

States are reviewed on a rotation, so a given state is not sampled every year, and each cycle carries fixed timelines for providers to respond.

PERM sampling works on a multi-state rotation, and providers face a set deadline to submit requested medical records once a case is selected, according to CMS's PERM guidance. Missing that window is one of the fastest ways to generate an automatic improper payment finding, regardless of whether the underlying claim was legitimate.

If your organisation could be sampled, prepare now to leverage expert healthcare IT services and HIPAA compliance that support secure evidence capture and transmission.

  • Designate PERM points of contact in advance, for both the state agency and any managed care plans involved.
  • Assemble sample record packages in a standard format so a request does not trigger a scramble.
  • Confirm submission channels, including esMD or another secure electronic route, work before you need them.

Form CMS-64, overpayments and the federal share

Form CMS-64 is how states report quarterly Medicaid expenditures and claim the federal share, and it is due within about one month after the end of each quarter, per state budget and expenditure reporting for Medicaid and CHIP. That thirty-day window is tight enough that any delay in closing out a quarter's adjustments tends to cascade into late or incomplete reporting.

Overpayments carry their own timing rule. Under 42 CFR §433.316(d)(2), states generally have one year from discovery to recover an overpayment before the federal share must be returned regardless of recovery status, and this clock runs differently once a case reaches final judgment through a Medicaid Fraud Control Unit (MFCU) action.

OIG audits repeatedly find the same weaknesses. A review of Mississippi's handling of MFCU-determined recoveries found the state had not reported and returned the federal share on several cases, and OIG's report recommended stronger internal controls and reconciliation procedures between the MFCU and the state's CMS-64 reporting team. The recurring pattern across these findings is not arithmetic error: it is a missing handoff between the unit that recovers the money and the unit that reports it.

  • Missing reconciliations between MFCU case files and CMS-64 adjustment lines.
  • Late reporting of overpayments discovered outside the normal quarterly cycle.
  • Unresolved deferred payments sitting outside any tracked register.

Pro Tip: Build a reconciliation register that links every MFCU or audit recovery to its corresponding CMS-64 line, with a named owner and a resolution date, before the next OIG review finds the gap for you.

Fraud referrals: timelines and coordination with MFCU

Contracts under 42 CFR §438.608(a)(7) require managed care plans to report suspected fraud, waste and abuse, and the referral recipient (a state Program Integrity Unit, an MFCU, or both) is usually set by contract. CMS's own fraud referral guidance recommends concurrent notice to both the PIU and the MFCU wherever a plan's contract allows it, so investigative and financial recovery tracks start at the same time rather than in sequence.

To meet both the contractual duty and CMS's expectations, build the referral process around three controls:

  1. Start an intake clock the moment potential fraud is detected, timestamped rather than dated to the day.
  2. Require a minimum referral package: the claims in question, the suspected pattern, and any supporting documentation, before the referral leaves the building.
  3. Keep a proof-of-transmission record showing exactly when and to whom the referral was sent.

CMS's managed care fraud referral toolkit suggests treating "prompt" as within two business days, a benchmark worth building into any SIU intake procedure rather than leaving the term undefined.

Building an audit-ready evidence package for renewal

CMS's renewal compliance template, described in evidence demonstrating compliance with regulatory requirements, sets out exactly what a state must produce when attesting to compliance: end-to-end process flows, system flows, and a sample renewal package that stands in for the whole population. CMS will monitor approved plans through 2026, so the evidence bundle needs to hold up over more than one review cycle.

Version control matters here as much as content. Policies change, systems get updated, and a reviewer comparing a 2024 process flow against a 2026 system demonstration will notice a mismatch immediately.

Evidence itemWhat it should show
End-to-end process flowEvery step from application to determination, with named roles
System flow diagramHow the eligibility system handles each step technically
Sample renewal packageA representative case file, redacted appropriately
Policy version logEffective dates for every policy referenced in the flows

A short internal checklist, mapped directly to this table, keeps a renewal submission from becoming a last-minute document hunt.

An audit-ready playbook for compliance teams

The controls that consistently reduce OIG findings are simple, but they need to be standing infrastructure rather than something assembled after a review letter arrives.

  • Case-to-CMS-64 reconciliation register: every recovery linked to its adjustment line, computed federal share, and audit trail, so a reviewer can trace money from investigation to report without asking a second question.
  • Standardised reviewer workpapers: dates, the reviewer's judgement in their own words, and a named owner for any unresolved item, fields that OIG audit teams look for by default.
  • SIU intake pack: the triage clock, the minimum referral fields, and proof of transmission, kept together rather than scattered across email threads.

Pro Tip: A single missing case file between an MFCU and a state reporting team is a more common audit finding than a calculation error, so governance and handoffs deserve at least as much attention as the numbers themselves.

Why traceability wins Medicaid audits

Across engagements with state agencies and managed care plans, the governance failures that trigger findings are rarely about the maths. They are about a case file that never made it from an investigator's desk to the reporting team, or a training log that exists somewhere but not where a reviewer can find it in the time given. Mapping the workflow so evidence sits where the reporting step needs it fixes more audit risk than any amount of double-checking totals. Start with a one-page readiness checklist against your next MCPAR or CMS-64 deadline and see what it turns up.

— Peter

How Keystone helps teams get audit-ready

Building every one of these registers, workpapers and evidence repositories in-house takes time most compliance teams do not have alongside their existing caseload. Videra Healthcare maps your reporting workflows directly, capturing evidence at the point of work rather than reconstructing it before a deadline, with reporting automation built around the same CMS templates covered here.

Keystoneconsulting

For teams that want hands-on support building the compliance programme itself, Keystone's consultancy engagements work alongside your compliance officer and RCC to design the monitoring work plans and evidence trails CMS expects. Request a readiness review to see where your next MDCT-MCR or CMS-64 submission stands today.

Sources

FAQ

What are the CMS requirements for a compliance program?

CMS requires managed care compliance programmes to include written policies, a designated compliance officer, a regulatory compliance committee, staff training, open communication channels, enforced disciplinary standards, and ongoing monitoring and auditing. These elements come from 42 CFR §438.608 and are typically written directly into state managed care contracts.

What are the main components of the Medicaid compliance program?

The core components are a compliance officer with direct reporting authority, a compliance committee that meets regularly, documented training, accessible reporting channels for staff, consistent disciplinary standards, and risk-based monitoring work plans. Each component needs a documentary trail, such as meeting minutes or training logs, to demonstrate it functions in practice rather than existing only on paper.

What are some examples of compliance issues in healthcare?

Common issues include missing reconciliations between recovered overpayments and CMS-64 reporting lines, late fraud referrals to a Program Integrity Unit or MFCU, and incomplete evidence packages for renewal attestations. OIG audits, including one covering Mississippi's MFCU recoveries, repeatedly point to governance handoffs rather than calculation errors as the recurring cause.

What is Medicare compliance?

Medicare compliance refers to the separate set of federal rules governing Medicare providers and plans, distinct from the Medicaid reporting streams covered in this guide, such as MCPAR, MLR and Form CMS-64. The two programmes share some oversight concepts, including fraud, waste and abuse prevention, but operate under their own statutes, contracts and reporting templates.