What Happened
In 2024, the Centers for Medicare & Medicaid Services (CMS) fundamentally restructured its Medicare Advantage oversight program. The agency shifted from auditing fifty plans annually to aiming for audits of all six hundred Medicare Advantage plans each year. To support this increase, CMS expanded its coding workforce from 40 to 2,000 personnel. Meanwhile, the Department of Justice and HHS formed a False Claims Act Working Group, and qui tam claims reached a record high.
This isn't an isolated incident. It's a systemic shift in enforcement that has already caught unprepared plans off guard.
Timeline
Pre-2024: CMS conducted risk-based audits of about fifty Medicare Advantage plans per year, creating an 8% annual audit probability for any given plan.
2024: CMS announced the expansion to universal annual audits, began recruiting and training coding staff, and initiated the transition to the new audit model. The False Claims Act Working Group was formed, and qui tam filings hit an all-time high.
Current state: Plans that previously faced audit once every twelve years now face annual scrutiny. The coding team expansion from 40 to 2,000 is nearly complete, indicating operational capacity to execute the universal audit strategy.
Which Controls Failed or Were Missing
The shift exposed three critical control failures across the Medicare Advantage sector:
Risk assessment recalibration. Plans designed compliance programs around an 8% annual audit probability. When that probability jumped to 100%, existing monitoring became inadequate. Plans that sampled 5% of claims for internal review can't scale that approach when every claim could face federal scrutiny.
Documentation retention and retrieval. Many plans maintained documentation standards sufficient for fifty audits annually across the sector. That meant individual plans optimized for infrequent audits. With annual reviews, documentation gaps that previously went undetected now surface immediately. The control failure: documentation policies built for exception-based audits, not continuous oversight.
Coding accuracy validation. With 2,000 federal coders now reviewing submissions, coding decisions that passed under light sampling now face systematic challenge. Plans relied on coder training and spot-checking but lacked the continuous validation controls necessary when every coding decision carries audit exposure.
What the Relevant Standards Require
Medicare Advantage plans operate under 42 CFR § 422, which requires compliance programs that include written policies, training, internal monitoring, and prompt response to compliance issues. The Office of Inspector General's General Compliance Program Guidance establishes seven fundamental elements, including conducting internal monitoring and auditing.
The critical requirement: your internal monitoring must be "effective." That term isn't defined by sample size or frequency in the regulation. It's defined by whether your program detects the problems the government would find.
When audit probability was 8%, a compliance program that caught 70% of coding errors might be considered effective. You'd likely never face an audit, and if you did, your demonstrated effort would matter. When audit probability is 100%, that same program guarantees findings. The regulatory obligation hasn't changed, but the operational definition of "effective" has shifted dramatically.
The False Claims Act (31 U.S.C. §§ 3729-3733) imposes liability for knowingly submitting false claims. The statute includes a knowledge standard: actual knowledge, deliberate ignorance, or reckless disregard. A compliance program that was adequate under light audit scrutiny may now constitute reckless disregard under universal audit conditions. You can't claim you didn't know about systematic coding errors when federal auditors will find them in twelve months.
Lessons and Action Items for Your Team
Recalculate your monitoring sample sizes. If you're sampling 5% of claims for internal review, you're not finding what CMS will find. Move to risk-stratified sampling that covers at least 25% of high-risk claim categories monthly. For diagnosis codes that trigger risk adjustment payments, consider 100% automated screening with manual review of exceptions.
Stress-test your documentation retrieval. CMS will request medical records to support coding decisions. Time yourself: can you produce complete, legible documentation for 100 randomly selected encounters within 48 hours? If not, your document management controls are inadequate. Implement automated completeness checks at the point of record closure, not months later during audit response.
Build a coding validation program that mirrors federal methodology. The 2,000 CMS coders are using the same code sets and guidelines you are. Hire external coding specialists to review a monthly sample using CMS audit protocols. When your validators disagree with your coders more than 5% of the time on risk-adjustment codes, you have a training or quality control gap.
Map qui tam risk indicators. Record-high qui tam filings mean employees, contractors, and providers are filing whistleblower claims. Your hotline data, exit interview themes, and provider complaint patterns are early warning indicators. If you're seeing internal concerns about upcoding, aggressive diagnosis capture, or documentation pressure, assume someone has already contacted a qui tam attorney.
Establish a False Claims Act response protocol. The new DOJ/HHS working group will coordinate enforcement. Your protocol should define: who leads the internal investigation, what triggers external counsel engagement, how you preserve relevant records, and when you consider voluntary self-disclosure. Don't build this protocol during an investigation.
The audit expansion isn't a temporary enforcement surge. It's the new baseline. Plans that treat this as a one-time adjustment will face the same compliance failures in 2026 that they're experiencing now. Build controls for continuous scrutiny, not periodic review.




