How CMS Changes Are Reshaping Payment Integrity Strategies
This white paper draws from insights shared during CERIS’s recent Becker’s Healthcare webinar, “Medicare and Medicaid Payment Integrity Shifts: Headlines vs Real-world Impact.” Panelists included Cereasa Horner, Director of Policy and Payment Integrity at CERIS, and Philo Hall and Kevin Malone, legal experts at Epstein Becker Green.
A New Era of Payment Integrity
As Medicare and Medicaid oversight accelerates, health plans are navigating an increasingly complex environment shaped by faster policy changes, evolving state requirements, and growing expectations for transparency. At the same time, CMS is placing greater emphasis on reducing improper payments before they occur, shifting from a traditional “pay and chase” method in favor of more proactive approaches.
While post-payment review remains an essential component of every payment integrity program, health plans are increasingly investing in prepay strategies to prevent claims leakage, strengthen audit readiness, and address growing regulatory scrutiny.
Yet the challenge facing payers isn’t simply keeping up with new regulations. It’s translating them into operational action. Today’s regulatory landscape requires close coordination across legal, compliance, claims operations, network management, and payment integrity teams. Health plans that align these functions are better positioned to reduce financial risk while maintaining trust and ensuring timely access to care.
This white paper explores the regulatory trends reshaping payment integrity, examines how those changes affect day-to-day operations, and outlines practical strategies health plans can use to strengthen compliance while building agile payment integrity programs.
Today’s Regulatory Environment
Historically, health plans could prepare for relatively predictable CMS rulemaking cycles, implementing operational changes through annual updates. That predictability is no longer the status quo. CMS is moving more quickly than ever before, driven by mounting pressure to reduce improper payments, protect taxpayer dollars, and expand oversight across Medicare and Medicaid programs.
“What used to be a predictable cycle of formal rulemaking from CMS has really shifted. We’re now seeing expanded use of audit findings and real-time data to accelerate policy updates between those cycles.” — Cereasa Horner, Director of Policy and Payment Integrity, CERIS
Along with formal regulations, payers must also closely monitor:
- Audit findings
- Agency memoranda
- Frequently Asked Questions (FAQs)
- Sub-regulatory guidance
- Enforcement actions
- Real-time policy updates
In many cases, these communications are influencing operational expectations just as significantly as formal rulemaking. As Cereasa shared in the discussion, “When you’re moving towards more real-time prevention, you really have to make sure that everyone is on the same page. Part of being on that same page is not only understanding the final rules that are coming out from CMS, but it’s also being able to be aware and interpret some of that sub-regulatory guidance.”
For Medicaid, complexity increases further because implementation often varies by state. States may adopt federal guidance on different timelines, or interpret requirements differently altogether. Organizations operating across multiple jurisdictions must navigate inconsistent compliance expectations, all while balancing two equally important objectives: demonstrating strong financial stewardship to prevent improper payments and ensuring timely access to medically-necessary care.
The result is a payment integrity environment that is becoming increasingly dynamic. Rather than reacting to annual regulatory updates, health plans must develop the operational agility to respond to continuous change. This is why payment integrity programs are increasingly being designed around layered approaches that combine prepay and post-pay interventions.
Looking Beyond the Headlines
While regulatory headlines often focus on individual policy announcements, it is advised to view regulatory change through a much broader lens. As Philo Hall explained, today’s regulatory landscape is influenced by multiple mechanisms simultaneously, including federal legislation, formal CMS regulations, agency guidance, enforcement activity, and state oversight initiatives. Each can introduce new operational expectations for payers.
“We have to operate knowing all the different pieces of our healthcare system and what instability they’re under, how much there’s a dynamic landscape and how much they’re changing.” — Philo Hall, Member of the Firm, Epstein Becker Green
Recent examples include the One Big Beautiful Bill Act, evolving Medicaid work requirements, changes to provider enrollment standards, state-directed payment reforms, provider tax limitations, and expanded fraud oversight initiatives. Federal actions involving California and Minnesota further illustrate how quickly enforcement priorities can affect state Medicaid programs and managed care organizations.
Understanding these developments requires more than tracking policy announcements for legal compliance. Each regulatory change can influence provider contracts, reimbursement policies, coding practices, operational workflows, documentation requirements, audit strategies, and resource allocation.
Rather than asking, “What changed?”, organizations should instead ask, “How does this change affect our business?” That distinction can make the difference between reactive compliance and proactive operational planning.
Assess Risk Before You React
When significant regulatory changes occur, payers often must take immediate action to avoid compliance issues with limited information. However, it is critical to first evaluate whether a particular policy applies to your organization and where true exposure exists.
“It’s really important to be very, very precise about first principles. What’s the product? What’s the market? What’s the regulatory hook?… Your actual exposure completely flows to what is the market that you’re talking about.” — Kevin Malone, Member of the Firm, Epstein Becker Green
Before taking action, work through this connected set of questions:
- Which line of business is affected — Medicare, Medicaid, Medicare Advantage, commercial, or ACA?
- Does this regulation actually apply to us, and what regulatory authority governs our obligations?
- Is the requirement contractual, or does it originate from CMS or state Medicaid rules?
- Does it affect our provider agreements?
The answers can vary significantly depending on the market. Medicare Advantage, Medicaid managed care, commercial products, and ACA plans all operate under different regulatory frameworks. Assuming a policy applies equally across every line of business can create unnecessary operational work, or worse, even introduce new compliance risk. As Kevin Malone cautioned, “You can create liability for yourself by doing things that you don’t actually have the legal authority or obligation to do.”
Operationalizing Regulatory Change
Regulatory changes rarely stop at compliance. Every policy update eventually influences claims operations, coding practices, documentation, provider engagement, legal review, and payment integrity workflows. Understanding those downstream effects is what transforms regulatory awareness into operational readiness.
One area receiving particular attention is CMS’ ongoing RADV audit activity. Rather than viewing these audits as isolated events, payers should separate their work into three distinct categories:
- Historical audit years: Completed audits prior to 2018, which are largely closed out but still offer valuable lessons about earlier documentation gaps and operational weaknesses.
- Active audit years: Current high-priority backlog, roughly 2018-2021, which requires significant operational resources to respond to requests, validate documentation, and support appeals.
- Future audit years: For 2022 and beyond, there is an opportunity to strengthen processes before similar issues re-emerge.
One of the webinar’s most important observations was that many audit findings are not new problems but unresolved problems. Instead of simply correcting individual claims, organizations should perform honest internal risk assessments that ask what known issues currently exist, which issues have already been corrected, and what risks remain unresolved. It is also worth evaluating whether documentation or coding patterns are recurring, and identifying which issues present the greatest financial exposure.
Separating Retrospective Recovery from Future Prevention
Many payment integrity departments attempt to manage historical audits while simultaneously preparing for future regulatory changes using the same personnel. The panelists recommended establishing separate operational workstreams instead. This includes a retrospective audit team focused on RADV responses, appeals, overpayments, audit requests, and historical documentation review. Additionally, a future-focused prevention team concentrated on documentation improvement, coding accuracy, provider education, quality assurance, internal controls, and preventive claim edits. This approach allows payers to address current obligations without sacrificing long-term operational improvements and avoids the common pitfall of both teams competing for the same limited staff.
Why Prepay Strategies Are Gaining Momentum
Health plans are increasingly implementing prepay strategies that identify potential payment issues before claims are finalized. Based on its work with health plans nationwide, CERIS has seen the majority of its clients evaluate or implement expanded prepay strategies as part of broader payment integrity initiatives.
These programs can help reduce avoidable payment leakage before claims are paid, improve documentation quality, strengthen audit readiness, and reduce downstream recovery efforts while supporting more consistent compliance. Based on CERIS’ experience, prepay strategies can help identify and prevent an estimated 2–3% of potential claims leakage before payment. Early intervention also helps reduce the provider abrasion caused by retrospective recoveries.
While post-payment audits remain an essential safeguard to identify claims leakage, health plans are increasingly shifting audit activities to prepay as part of a single, layered payment integrity strategy to reduce improper payments
Payment Integrity Requires Collaboration
Another consistent theme throughout the webinar discussion was that payment integrity can no longer function in isolation. Today’s regulatory environment requires close collaboration among payment integrity, legal, compliance, claims operations, network management, special investigations units (SIU), and executive leadership.
While legal, compliance, and payment integrity should remain independent functions, they are most effective when working in close partnership. Each brings distinct expertise: compliance interprets regulatory requirements, legal evaluates contractual authority and liability, and payment integrity identifies billing patterns and payment risk. Operations translate those insights into workflow improvements, while network management helps maintain productive provider relationships.
Without ongoing communication across these functions, health plans risk creating conflicting priorities, duplicating efforts, or introducing unintended compliance issues. As regulatory complexity increases, organizational alignment becomes a strategic advantage, not just an operational necessity.
Provider Partnerships for Prevention
As health plans strengthen operations, maintaining positive provider relationships becomes increasingly important. Organizations implementing new edits or reimbursement policies often encounter provider frustration when changes are perceived as unnecessary barriers rather than compliance safeguards. The panelists encouraged organizations to focus on building blocks, not roadblocks.
Strong provider relationships begin with:
- Clear reimbursement policies
- Transparent documentation expectations
- Consistent communication
- Education before enforcement
- Feedback loops that help providers improve documentation quality
Effective claim edits improve payment accuracy, not simply increase denials. Analyzing denial trends and documentation patterns helps payers identify opportunities for provider education rather than relying solely on punitive enforcement.
Prepay strategies are most successful when providers understand both the policy requirements and the rationale behind them. Health plans that can obtain medical records quickly and consistently are better positioned to make timely prepay reviews and minimize disruption to providers.
Contracts Are Your Operational Foundation
As regulatory expectations evolve, provider contracts have become increasingly important operational tools. Ambiguous language surrounding payment authority, coding requirements, audit rights, and reimbursement methodologies can create unnecessary disputes and increase compliance risk.
Organizations should regularly review contract provisions related to:
- Audit definitions and lookback periods
- Coding authority
- Payment suspension authority
- Overpayment recovery
- Payment policy incorporation by reference
- Fee schedule updates and mid-year CMS policy changes
- Dispute resolution procedures
It is important to clearly define how Medicare payment policies are incorporated into provider agreements, particularly as CMS updates coding guidance and reimbursement methodologies throughout the year. Well-defined contracts give payers stronger audit defensibility while reducing provider confusion and supporting more consistent payment integrity operations.
Practical Recommendations for Health Plans
While every health plan faces unique regulatory and operational challenges, several best practices emerged throughout the discussion. The following recommendations can help payers strengthen their payment integrity programs and improve readiness for an evolving compliance landscape.
- Monitor sub-regulatory guidance, not just final regulations
- Conduct recurring internal risk assessments
- Separate retrospective audit work from future-prevention initiatives
- Document corrective actions thoroughly
- Strengthen collaboration among legal, compliance, claims, and payment integrity teams
- Review provider contracts regularly to ensure they reflect current regulatory expectations
- Clarify audit authority, payment authority, and documentation requirements
- Invest in provider education and communication
- Develop layered payment integrity strategies that integrate both prepay and post-pay capabilities
- Treat payment integrity as an enterprise-wide governance function rather than solely a claims operation
Conclusion
Regulatory complexity isn’t expected to slow. As CMS continues to evolve payment integrity expectations, health plans that invest in proactive governance, cross-functional collaboration, and prevention-focused strategies will be better positioned to adapt quickly, reduce payment risk, and build more resilient payment integrity programs. Health plans that successfully align legal, compliance, claims, provider relations, and payment integrity functions will be better positioned to reduce financial risk, strengthen audit readiness, maintain provider trust, and deliver more sustainable payment integrity outcomes.
About CERIS
As health plans navigate an increasingly complex regulatory environment, CERIS combines more than 30 years of payment integrity expertise with proprietary claims intelligence, established provider partnerships, and its universal chargemaster containing billions of charge items from more than 95% of the nation’s hospitals, to help organizations strengthen both prepay and post-pay strategies. CERIS helps payers improve audit readiness, reduce payment risk, and make more informed payment decisions.
