Maryland
Maryland Office of Legislative Audits
Published August 9, 2024

Maryland Department Of Health Pharmacy Services Audit Report

Learn how the AI-generated research projects were created

Overall Conclusion

MDH’s pharmacy services program exhibits governance and control weaknesses across manual claims processing, provider licensure verification, program audits, and MADAP rebates, leading to substantial overpayments and potential noncompliance with regulations. A cybersecurity finding is redacted in the public report. Some prior-year findings were addressed, while others were repeated, and MDH and its programs indicate corrective actions and ongoing improvements.

Source Document

Audit Scope

The audit is a fiscal compliance examination of the Maryland Department of Health (MDH) pharmacy services for the period July 1, 2019 through December 31, 2022. It covers MDH’s pharmacy programs administered by the Medical Care Programs Administration (MCPA) and Prevention and Health Promotion Administration (PHPA), including the Maryland Medicaid Pharmacy Program (MMPP), Medicaid Managed Care Program (MCPA), Maryland AIDS Drug Assistance Program (MADAP), Breast and Cervical Cancer Diagnosis and Treatment Program (BCCDTP), and Kidney Disease Program (KDP). The audit evaluated claims adjudication and processing, vendor system controls and security, rate setting, program monitoring and audits, and rebate processing for these five programs. It also encompassed the nine Managed Care Organizations (MCOs) and analyzed rebates for both fee-for-service programs and MCOs. The period payments (fiscal year 2022) totaled approximately $631 million in claim payments across the four fee-for-service programs and approximately $711.5 million in capitation payments related to pharmacy services for MCOs. The audit also reviewed the status of findings from the preceding audit (August 2020) and included consideration of the December 2021 ransomware security incident. The public report notes that cybersecurity findings have been redacted in accordance with State law, with related details addressed in an unredacted version.

Key Findings Summary

1

Finding 1 – The Medical Care Programs Administration did not ensure manually processed Maryland Medicaid Pharmacy Program (MMPP) claims were proper, resulting in overpayments of approximately $397,000 related to 11 of the 15 claims tested.

2

Finding 2 – MDH did not have procedures to ensure that prescribing providers were licensed prior to approving pharmacy claims for payment.

3

Finding 3 – MDH did not audit three of the four fee-for-service programs’ pharmacy claims, did not analyze claim reversals, and did not use available drug utilization data to identify improper claims.

View the Findings tab to see all 5 findings

AI-Assisted

Generated by gpt-5-nano

AI Scope Summary

Assess and improve MDH’s fiscal compliance and internal controls over pharmacy services across five programs, evaluate adherence to licensing and purchasing regulations, review rebate administration, and determine progress on resolving prior audit findings.

AI-Generated Insight

This audit underscores material gaps in MDH’s oversight of pharmacy claims, licensing checks, rebate administration, and data analytics. The mixed progress on prior findings, combined with a redacted cybersecurity finding, signals both improvements and ongoing risk areas. Strengthening independent reviews of manual claims, expanding program audits, tightening licensure verification at the point of payment, and robust rebate collections are critical to reducing improper payments and safeguarding program integrity.

Audit Objectives

1

Examine MDH's financial transactions, records, and internal controls related to MDH's pharmacy services.

2

Evaluate MDH's compliance with applicable State laws, rules, and regulations governing MDH's pharmacy programs.

3

Assess the operations of the MDH pharmacy vendor system, including security, claims adjudication and processing, manual overrides, rate setting, program monitoring, and rebate processing for the four fee-for-service programs and MADAP.

4

Determine the status of findings from the preceding audit and assess MDH's corrective actions.

Audit Findings (5)

1

Finding 1 – The Medical Care Programs Administration did not ensure manually processed Maryland Medicaid Pharmacy Program (MMPP) claims were proper, resulting in overpayments of approximately $397,000 related to 11 of the 15 claims tested.

2

Finding 2 – MDH did not have procedures to ensure that prescribing providers were licensed prior to approving pharmacy claims for payment.

3

Finding 3 – MDH did not audit three of the four fee-for-service programs’ pharmacy claims, did not analyze claim reversals, and did not use available drug utilization data to identify improper claims.

4

Finding 4 – MDH did not ensure that drug manufacturers provided timely and proper MADAP drug rebate payments.

5

Finding 5 – Redacted cybersecurity-related finding.

Recommendations (9)

1

Recommendation 1a – MDH should perform independent documented reviews of manually processed claims.

2

Recommendation 1b – MDH should recover any overpayments identified, including those noted above.

3

Recommendation 2 – Establish procedures to ensure prescribing providers are licensed as required by program regulations prior to paying pharmacy claims (repeat).

4

Recommendation 3a – Establish procedures to periodically audit each program’s pharmacy claims on a test basis (repeat).

5

Recommendation 3b – Investigate pharmacies with below-average reversal rates and take appropriate follow-up action (repeat).

6

Recommendation 3c – Utilize all available data to help identify improper MMPP pharmacy claims including fraud, waste, and abuse (repeat).

7

Recommendation 4a – Establish procedures to ensure that all required drug manufacturers pay rebates accurately and timely (repeat), including development of accounts receivable records to monitor outstanding rebates and pursue collection activities.

8

Recommendation 4b – Pursue collections of any outstanding rebates (repeat).

9

Recommendation 5 – Redacted cybersecurity-related recommendation.