Maryland Department of Health Medical Care Programs Administration Audit Report
Learn how the AI-generated research projects were createdOverall Conclusion
MCPA’s accountability and compliance level was unsatisfactory.
Source Document
Audit Scope
Fiscal period August 1, 2018 through March 31, 2022; MDH – Medical Care Programs Administration (MCPA); focus on Medicaid Management Information System II (MMIS II) security and controls, recipient and provider eligibility, third-party recoveries, hospital and nursing facility payments, Community First Choice and Medical Day Care; excludes MDH – Office of the Secretary and Other Units; results include ransomware incident impact and related redactions; methodology described in the report.
Key Findings Summary
MCPA did not have effective processes to identify, prevent, and recover questionable Medicaid payments, including $7.1 million in payments on behalf of incarcerated and deceased recipients.
MCPA did not adequately monitor the hospital claims audit contractor and had not collected or recovered improper claims identified by the contractor totaling $6.9 million.
The Medical Care Programs Administration (MCPA) did not ensure that all referrals of potential third-party health insurance information were investigated and recorded in the Medicaid Management Information System (MMIS II), which could result in MCPA improperly paying claims that should have been paid by a third party.
View the Findings tab to see all 10 findings
AI-Assisted
AI Scope Summary
Build on this audit by strengthening Medicaid integrity across third-party liability interfacing, questionable payments recovery, recipient eligibility processing, and program oversight (CFC, MDC, and hospital claims), while ensuring robust information security practices and rapid remediation following security incidents in future audits.
AI-Generated Insight
The Maryland MCPA audit identifies significant gaps in third-party liability interfacing, eligibility and payment controls, and oversight of waivers and hospital claims, compounded by a ransomware incident that disrupted operations and documentation. The public redaction of cybersecurity findings underscores ongoing risks that require strengthening controls and timely corrective actions in future audits.
Audit Objectives
To examine the Maryland Department of Health (MDH) – Medical Care Programs Administration (MCPA) for the period August 1, 2018 through March 31, 2022, including its financial transactions, records, and internal controls, and to evaluate compliance with applicable State laws, rules, and regulations.
To assess MCPA’s primary administrative functions, including recipient and provider eligibility, the Medicaid Management Information System (MMIS II) security and controls, third-party insurance recoveries, and payments for Medicaid recipients in hospitals, nursing facilities, in-home and community-based settings, with expenditures in fiscal year 2022.
To review the status of prior audit findings and determine whether non-cybersecurity-related findings were satisfactorily addressed or repeated.
To evaluate oversight of program areas and contractors related to Community First Choice (CFC), Medical Day Care, nursing facilities and hospital claims, including the monitoring of claim audits and potential recoveries.
To summarize the ransomware security incident and its impact on audit evidence and records, including limitations due to redacted cybersecurity findings.
Audit Findings (10)
MCPA did not have effective processes to identify, prevent, and recover questionable Medicaid payments, including $7.1 million in payments on behalf of incarcerated and deceased recipients.
MCPA did not adequately monitor the hospital claims audit contractor and had not collected or recovered improper claims identified by the contractor totaling $6.9 million.
The Medical Care Programs Administration (MCPA) did not ensure that all referrals of potential third-party health insurance information were investigated and recorded in the Medicaid Management Information System (MMIS II), which could result in MCPA improperly paying claims that should have been paid by a third party.
MCPA did not ensure that changes to recipient Medicaid eligibility information were processed timely and accurately.
MCPA had not established adequate oversight to ensure that all Community First Choice program recipients received personal assistance services in accordance with their plans of service.
MCPA did not monitor the utilization control agent contractor to ensure continued stay reviews of Medicaid recipients receiving services from nursing facilities were performed timely.
MCPA did not have an established process to ensure costly recipient ventilator care claims submitted by nursing facilities were valid, as required by State regulations.
MCPA did not conduct the required audits of Medical Day Care and Supports Planning providers, and the related audit policy and procedures were not sufficiently comprehensive.
Redacted cybersecurity-related finding.
Redacted cybersecurity-related finding.
Recommendations (14)
Monitor the Utilization Control Agent (UCA) contractor to ensure continued stay reviews are performed timely and assess any applicable liquidated damages.
Establish procedures to periodically validate ventilator care claims submitted by nursing facilities and recoup any unsupported or improper payments.
Audit Medical Day Care (MDC) providers in accordance with policy and test all MDC provider claims since the preceding audit.
Enhance the MDC audit policy to define scope and testing methodology and require expanded testing when significant deficiencies are identified.
Adequately monitor the hospital claims audit contractor and obtain all deliverables required by the contract.
Pursue recovery of overpaid hospital claims identified by the audit contractor in a timely manner.
Interface all third-party health insurance information provided by the third-party liability vendor with MMIS II.
Record all MCO insurance referrals in MMIS II in a timely manner.
Implement a monthly review of missing Social Security Numbers (SSNs) and refer cases to the Department of Human Services (DHS) and Local Health Departments (LHDs) for investigation.
Develop and implement a standalone platform or process to document investigations of questionable recipient eligibility to support timely corrective actions.
Establish a process to identify, prevent, and recover improper fee-for-service payments related to incarcerated recipients.
Document efforts to identify and remove deceased recipients from Medicaid and pursue recovery of improper payments after the recipients’ dates of death.
Ensure that recipient eligibility information is updated timely and accurately in MMIS II, and correct errors identified during supervisory reviews.
Establish a process to monitor Community First Choice (CFC) nurse monitoring and ensure all recipients are monitored; address long-standing non-compliance at Local Health Departments.