Maryland
Maryland Office of Legislative Audits
Published November 2, 2023

Maryland Department of Health – Medical Care Programs Administration Audit

Learn how the AI-generated research projects were created

Overall Conclusion

The audit concluded that the Maryland Department of Health’s Medical Care Programs Administration (MCPA) had an unsatisfactory level of accountability and compliance under the audit rating system, with multiple significant findings related to third-party liability interfaces, improper payments, eligibility processing, provider oversight, and contract monitoring. The status report indicates ongoing corrective actions with targeted completion between mid-2024 and mid-2025 for non-cybersecurity findings, while cybersecurity findings were redacted in the public copy. OLA will reassess follow-up viability in August 2024 based on MDH implementation status.

Source Document

Audit Scope

Original audit scope covered MDH's Medical Care Programs Administration for the period August 1, 2018 to March 31, 2022, focusing on program integrity, third-party liability interfacing, eligibility processing, and provider audits. The status update as of April 12, 2024 discusses the ongoing implementation of corrective actions for the eight non-cybersecurity findings and redacted cybersecurity-related findings; a follow-up review is not being pursued immediately but an updated status report is expected in August 2024 to determine the practicality of a follow-up.

Key Findings Summary

1

Finding 2: MCPA did not have effective processes to identify, prevent, and recover questionable Medicaid payments, including $7.1 million in payments on behalf of incarcerated and deceased recipients.

2

Finding 8: MCPA did not adequately monitor the hospital claims audit contractor and had not collected or recovered improper claims identified by the contractor totaling $6.9 million.

3

Finding 9: Redacted cybersecurity-related finding.

View the Findings tab to see all 10 findings

AI-Assisted

Generated by gpt-5-nano

AI Scope Summary

Assess the MDH MCPA’s accountability and compliance, evaluate the status of corrective actions for prior unsatisfactory findings, and identify ongoing weaknesses in third-party liability interfacing, eligibility processing, provider audits, and program integrity to inform follow-up oversight.

AI-Generated Insight

This report highlights persistent gaps in program integrity and data governance within Maryland's Medicaid operations, especially around third-party liability interfacing with MMIS II, timely eligibility updates, and monitoring of providers and contractors. The agency has initiated corrective actions, including staffing augmentations, new agreements (e.g., Nurse Monitoring Agreement), and planned UCA and ventilator-audit processes, and is pursuing a modular MMIS to enable better prevention and recovery of improper payments. The public copy's cybersecurity redactions underscore ongoing sensitivity around security incidents but also indicate broader governance improvements are needed. The findings justify targeted, auditable actions and a structured follow-up cadence (August 2024 and beyond) to safeguard program dollars and ensure compliance with Maryland laws and regulations.

Audit Objectives

1

Assess the Maryland Department of Health's Medical Care Programs Administration (MCPA) accountability and compliance with State laws and regulations to determine the agency's fiscal accountability.

2

Determine the status and effectiveness of corrective actions implemented for findings from the prior audit with an unsatisfactory rating, and assess the planning and timeliness of the implementation.

3

Identify ongoing weaknesses and risk areas related to third-party liability interface, eligibility processing, provider audits, and program integrity to inform follow-up reviews and oversight.

Audit Findings (10)

1

Finding 2: MCPA did not have effective processes to identify, prevent, and recover questionable Medicaid payments, including $7.1 million in payments on behalf of incarcerated and deceased recipients.

2

Finding 8: MCPA did not adequately monitor the hospital claims audit contractor and had not collected or recovered improper claims identified by the contractor totaling $6.9 million.

3

Finding 9: Redacted cybersecurity-related finding.

4

Finding 1: The Medical Care Programs Administration (MCPA) did not ensure that all referrals of potential third-party health insurance information were investigated and recorded in the Medicaid Management Information System (MMIS II), potentially resulting in improper payments.

5

Finding 3: MCPA did not ensure that changes to recipient Medicaid eligibility information were processed timely and accurately.

6

Finding 4: MCPA had not established adequate oversight to ensure that all CFC program recipients received personal assistance services in accordance with their plans of services, including nurse monitoring.

7

Finding 5: MCPA did not monitor the utilization control agent contractor to ensure continued stay reviews of Medicaid recipients in nursing facilities were performed timely.

8

Finding 6: MCPA did not have an established process to ensure costly recipient ventilator care claims submitted by nursing facilities were valid, as required by State regulations, and did not recoup unsupported or improper payments.

9

Finding 7: MCPA did not conduct the required audits of Medical Day Care (MDC) and Supports Planning providers, and the related audit policy and procedures were not sufficiently comprehensive.

10

Finding 10: Redacted cybersecurity-related finding.

Recommendations (14)

1

Recommendation for Finding 7: Ensure MDC and Supports Planning provider audits are conducted per policy; document scope and expand testing; update SOPs and provide ongoing staff training.

2

Recommendation for Finding 8: Actively monitor the hospital claims audit contractor, obtain all deliverables, and pursue recovery of improper claims; continue regular coordination with OIGH.

3

Recommendation for Finding 9: Redacted cybersecurity-related finding – no public recommendations available.

4

Recommendation for Finding 10: Redacted cybersecurity-related finding – no public recommendations available.

5

Recommendation for Finding 2a: Ensure that instances of recipients with missing SSNs are referred to DHS and the LHDs for investigation; establish a monthly review cycle and monitor corrective action cases.

6

Recommendation for Finding 6: Establish ventilator claim audits and recoupments for unsupported payments; implement comprehensive SOPs with defined pass/fail metrics and CAP requirements.

7

Recommendation for Finding 1: Ensure that all third-party health insurance information provided by the third-party liability vendor is interfaced with MMIS II, resolve the carrier text file interface, reconcile data discrepancies, and test the interface before deployment.

8

Recommendation for Finding 1 (b): Ensure that all MCO insurance referrals are recorded into MMIS II timely, and continue progress on automating the referral process using the 270/271 format once the carrier code file issue is resolved.

9

Recommendation for Finding 2b: Document reviews of investigations of questionable recipient eligibility and support proper corrective action using a standalone platform; implement timely action.

10

Recommendation for Finding 2c: Develop a process to identify, prevent, and recover improper fee-for-service payments related to incarcerated recipients; align with upcoming modular MMIS requirements.

11

Recommendation for Finding 2d: Continue monthly monitoring of deceased recipient cases and formalize processes for closing or redetermining cases, including management of households with deceased primary members.

12

Recommendation for Finding 3: Ensure that recipient eligibility information is updated timely and accurately in MMIS II; implement testing methodologies for CTAD reviews and monthly tracking reports.

13

Recommendation for Finding 4: Establish Nurse Monitoring Agreement with Local Health Departments and have Health Officers sign by the targeted date; update LTSSMaryland tools to identify non-compliant cases.

14

Recommendation for Finding 5: Monitor the Utilization Control Agent (UCA) contractor to ensure CSRs are completed timely; assess potential liquidated damages; develop an Ad Hoc MMIS report to improve data reconciliation.