OIG brought its managed care oversight map to the RISE West stage

Ann Maxwell, deputy inspector general for evaluation and inspections at the HHS Office of Inspector General (OIG), and Carolyn Kapustij, senior advisor for managed care at OIG, took the RISE West 2026 stage on Sept. 3 in San Diego for the morning keynote. They presented together for the full hour on the agency’s current oversight priorities in managed care, with the data behind each one on screen.

They came to trade information, not to keep score 

Both speakers set the tone up front. OIG sees itself as an agent of change rather than a fault finder. The reason for standing in front of a room of Medicare Advantage (MA) professionals, they said, is exchanging information so systemic risk surfaces earlier.

That framing held through the session. The tone stayed collegial even when the findings were uncomfortable.

The scale explains the attention

MA now covers more than half of eligible Medicare beneficiaries, MedPAC continues to find payments running higher per person than traditional Medicare, and political and congressional interest sits at a high. Federal agencies are coordinating their fraud work across programs.

The speakers added the piece plans feel first. The sophisticated schemes built in fee-for-service Medicare are moving into MA, and the agency is watching them arrive.

Their strategy rests on three pillars: supporting access to care, financial oversight, and data accuracy. Everything in the hour hung off those three.

Access to care took more of the hour than most expected 

Prior authorization came first. OIG published work this summer on post-acute care denials, and the statistic attendees wrote down was not the denial rate. It was the share of those denials plans reversed once patients appealed. High enough, the speakers said, to make the process look less like a safeguard and more like a hurdle. The agency is now using plan-level data to study how plans handle those requests.

Provider directories came next. OIG has surveyed behavioral health providers and reviewed maternal health network lists in Medicaid managed care, and in both cases a meaningful share of listed providers turned out to be unavailable, unreachable, or not in network at all. CMS agreed with the recommendations. Anyone tracking the new federal directory requirements heard the enforcement rationale in real time.

The money questions 

Marketing. OIG has watched broker and agent compensation since a Senate report put it on the map, and its 2024 fraud alert covered steering and referral payments. The newer concern points the other way. The speakers described plans trimming or eliminating commissions in ways discouraging enrollment by higher-cost beneficiaries. Two evaluations of marketing practices are underway.

Supplemental benefits. These have grown fast, MedPAC has flagged the reporting gaps, and OIG has audits running on reporting compliance, over-the-counter debit cards, and in-home support services, including the background check question.

Durable medical equipment. Fraud stays concentrated here, and the agency has a national white paper and a review of CMS and plan collaboration in the works.

The criminal cases. The speakers walked the room through the schemes behind recent national takedowns, including one built on stolen beneficiary identities at a scale the slide had to abbreviate. The lesson they drew was simpler than the numbers: the schemes follow the money into managed care. 

The part risk adjustment teams leaned in for

OIG has completed dozens of audits of diagnoses looking clinically improbable on their face, the kind appearing only on outpatient claims with no supporting care around them. The error rates on screen drew a reaction from the room.

Then came the slide attendees photographed. The next audit areas are set, and the speakers named them: diagnoses coming out of in-home health risk assessments, chart review records, and whether treatment followed a coded diagnosis at all.

They also spent a moment on self-disclosure, pointing to a large resolution this year where the organization brought the issue to OIG itself and earned credit for doing so. The protocol has been available for years. It stays underused.

The recommendation they keep making 

Complete data makes oversight possible. Provider identifiers on encounter records still go missing in the service categories carrying the most risk, plans already collect the information, and CMS does not require them to submit it. Getting that requirement in place remains one of OIG’s top unimplemented recommendations, and the speakers made clear they have not let it go.

How they closed

Compliance came last, and the tone shifted toward partnership. OIG released updated MA compliance program guidance in February, its first major refresh of industry guidance since 1999, and the speakers pointed to it as the working playbook for network adequacy, marketing, risk adjustment, and data validation.

On artificial intelligence, their message was sequencing. Data validation, documentation, and trained staff come before an organization turns AI loose inside its own oversight.

Kapustij closed on reciprocity. Plans see their own corner of the program. OIG and CMS see patterns across all of it. When both sides share, she said, the industry builds a shield against fraud. Then came the invitation: bring what you are seeing to OIG directly.

The exchange kept going after the session ended, in the hallway, with the speakers taking questions one at a time.

RISE puts RADV defense, documentation integrity, and revenue integrity on the floor at the 27th Risk Adjustment Forum, October 27-29, in Orlando, including a live audit simulation and sessions on AI governance in coding operations.