The recurring PBM oversight problem is not simply drug-price variation; it is the inability of Medicaid agencies to see, validate, and enforce what happens between claim adjudication, pharmacy payment, encounter reporting, rebate invoicing, and managed-care rate setting. Across 10 reports and 53 findings, the most consistently supported pattern is inadequate transparency and contract governance over PBM pricing, fees, adjustments, and subcontract terms.
The evidence identifies substantial control failures at several points in the pharmacy-payment lifecycle. Texas, Pennsylvania, and Oregon reported pricing or contractual structures that obscured final pharmacy payments, fees, or Medicaid-specific accountability. Other audits found incomplete encounter-data validation, weak claim edits and postpayment surveillance, missed manufacturer rebates, and insufficient assurance over the systems and third parties that process sensitive pharmacy and financial data. The highest-priority audit work is therefore transaction-level: trace PBM-adjudicated claims to pharmacy remittances and final system disposition, then reconcile the same claims through rebate invoicing and collection.
Quantified findings should be read carefully. New York reported $183.7 million in uncollected Medicaid drug rebates during its audit period, but that audit-period total may overlap with several component missed-rebate amounts and should not be added to them. Separately, Missouri and Maryland identified $572,170 in improper payments in the findings grouped as pharmacy-claim payment integrity. Most findings had no extracted dollar amount, so the financial record understates the breadth of operational risk. [Report 115] [Report 80] [Report 83]
A pharmacy benefit manager (PBM) administers functions that can include pharmacy-network management, claim adjudication, payment arrangements, drug-utilization controls, encounter reporting, and rebate-related data flows. In Medicaid managed care, those functions often sit between a managed care organization (MCO), pharmacies, manufacturers, state Medicaid systems, and actuarial rate-setting staff. Oversight fails when an agency can observe only aggregate performance or reported expenses rather than the final disposition of individual pharmacy claims.
The practical consequence is that an agency may lack assurance over whether pharmacy expenses reflect what pharmacies ultimately retained, whether returned funds or adjustments are attributed to Medicaid, whether encounter data are complete, and whether rebate-eligible claims reach the manufacturer invoicing process. The Texas State Auditor’s Office found that an effective-rate arrangement aggregated Medicaid and non-Medicaid claims, reducing transparency over final pharmacy payments; the Pennsylvania Department of the Auditor General similarly reported undisclosed spread pricing and overstated pharmacy data where pharmacy claims were not effectively monitored. [Report 7] [Report 65]
This review covers PBM-specific reports as well as Medicaid pharmacy, rebate, managed-care, rate-setting, and information-technology control audits. Direct PBM evidence is strongest in Texas, Pennsylvania, and Oregon. Pharmacy claims, rebate, and systems findings from Maryland, Missouri, New York, and Virginia are included because they test the data, payment, recovery, and service-provider control environment on which PBM oversight depends.
Contextual figures—such as Missouri’s approximately $959 million in 2016 outpatient prescription-drug payments—describe program scale, not improper payments or estimated loss. Direct financial findings are limited: only 16 of the 53 scoped findings contain extracted financial values. [Report 80]
This is the strongest recurring theme, supported by 11 findings in four reports across Texas, Pennsylvania, and Oregon. The common failure was not merely a missing disclosure. It was the absence of an enforceable, Medicaid-specific line of sight from an adjudicated claim to the amount ultimately retained by the pharmacy, the PBM, and other parties.
The Texas State Auditor’s Office’s Blue Cross Blue Shield of Texas audit found that $26.4 million in fiscal year 2018 pharmacy expenses reported in the Financial Statistical Report (FSR) did not reflect the final amount paid to pharmacies. A year-end effective-rate aggregation process required pharmacies to return funds to the PBM, while combining Medicaid and non-Medicaid business in a manner the Commission considered unallowable. The reported encounter data did not include returned funds, and the PBM methodology did not identify the portion attributable to STAR Kids or other Medicaid programs. [Report 7]
Pennsylvania’s PBM services audit reached a comparable conclusion through a different operating model: the Department of Human Services did not effectively monitor pharmacy drug claims, resulting in undisclosed spread pricing, overstated pharmacy data, and limited transparency. The report also found that the agency did not effectively monitor MCO-PBM contracts, while PerformRx was transparent to pharmacies about transmission fees but not to the MCOs and the Department. [Report 65]
Oregon’s Secretary of State, Audits Division, described a fragmented structure involving 16 coordinated care organizations, six PBMs, hundreds of pharmacies, and several other entities—too complex for the state to efficiently measure value. The audit found insufficient high-risk PBM monitoring and incomplete contract provisions, notwithstanding improvements in contract language from 2020 through 2023. It also reported significant reimbursement variation by PBM and pharmacy type. [Report 100]
The synthesis is clear: aggregate reporting cannot substitute for claim-level transparency when PBM arrangements include adjustments, fees, returned funds, or multi-line-of-business pricing methodologies.
This theme is supported by seven findings in four Texas reports, although the evidence comes from one jurisdiction. The risk is that incomplete pharmacy encounter data and delayed financial reconciliation can distort both operational oversight and managed-care payment decisions.
The Texas State Auditor’s Office’s managed-care contract-process audits found that the Commission had planned to use External Quality Review Organization (EQRO) information and encounter-data validation to monitor MCOs, but had not fully implemented those plans. The reports also called for PBM performance audits, corrective-action policies based on agreed-upon procedures (AUP) engagements, and verification that corrective actions were implemented. [Report 6] [Report 26]
The Blue Cross Blue Shield of Texas audit provided a concrete example: 1,297 compound-drug encounters totaling $132,511 were not reported because of coding errors. The health plan did not work with the Commission to correct and resubmit the encounters. That amount represents the value of the unreported encounters, not a finding of improper payment. [Report 7]
The Texas rate-setting audit then showed how data-quality gaps can travel upward. AUP engagements and year-end MCO financial-statement reconciliations for 2018 through 2021 were not completed before rate setting, and some reconciliations occurred more than a year after year-end. Results were not consistently communicated to the Actuarial Analysis Department. [Report 114]
The broader lesson is that encounter accuracy, corrective-action follow-up, and rate-setting governance are one control chain—not separate administrative tasks.
This theme is supported by 10 findings in four reports across Texas, Maryland, and Virginia. It is not exclusively a PBM finding, but it is foundational: agencies cannot reliably test PBM performance if the systems, data repositories, and service providers handling claims and financial information lack controlled change, access, and security practices.
The Texas managed-care contract-process audit found that change authorizations and testing for programming changes were not consistently documented. Its substantially similar companion report also characterized change-management documentation as needing improvement. [Report 6] [Report 26]
The Virginia Auditor of Public Accounts reported material weaknesses in the Department of Medical Assistance Services’ information-security program and database security. The audit called for timely closure of corrective actions, formal database-security policies and baselines, scheduled configuration reviews, annual access reviews, and remediation of vulnerabilities. It also identified significant deficiencies in fiscal-agent oversight and third-party risk management. [Report 86]
Maryland’s pharmacy-services audit includes a redacted cybersecurity-related finding. Because the underlying issue and recommendation are redacted, it should not be used to infer a specific PBM or pharmacy-system condition. It does, however, reinforce the need to obtain enough independent assurance to evaluate the systems that administer pharmacy operations. [Report 83]
This is a control-environment risk: weak security and third-party governance can undermine the completeness, integrity, availability, and confidentiality of the very records needed to test PBM pricing and claims outcomes.
This theme is supported by 10 findings in two reports across Maryland and New York, with the most significant quantified exposure in the evidence base. Rebate controls failed when agencies did not reconcile source claims, data extracts, contractor exceptions, invoices, receivables, and collections as a continuous process.
The New York State Comptroller audit reported $183.7 million in uncollected Medicaid drug rebates during the audit period due to errors and weaknesses in the rebate-collection process. The audit identified approximately $119 million in missed rebates from claim-extraction errors between April 2018 and October 2020, as well as an approximately $109.4 million missed-rebate issue involving zero-dollar-paid values sent to the rebate contractor despite actual payments of about $91.1 million. [Report 115]
The same New York audit identified additional failure points: incorrect drug-unit reporting; invalid National Drug Code (NDC) and procedure-code combinations; unclassified drug codes; omitted Program of All-Inclusive Care for the Elderly (PACE) claims; claims rejected or not reported during transition to Magellan; and same-quarter reversals ignored during invoicing. For example, 114,435 claims not reported or rejected during the transition were associated with about $6.4 million in missed rebates. [Report 115]
Maryland’s pharmacy-services audit found that the Department of Health did not ensure manufacturers made timely and proper Maryland AIDS Drug Assistance Program rebate payments, and recommended accounts-receivable records and collection follow-up. [Report 83]
The central risk is not one flawed interface. It is the absence of an end-to-end reconciliation that proves every eligible claim was extracted, accepted, invoiced, recorded as a receivable, and collected.
This theme is supported by six findings in two reports across Missouri and Maryland. These are direct payment-integrity weaknesses that can create improper payments and also suppress rebates when drug information is incomplete or invalid.
The Missouri State Auditor found that the Department of Social Services lacked controls to require NDCs for all physician-administered drug claims. About $170,000 in 2016 claims were paid as procedural claims without NDCs, limiting manufacturer rebate billing; the report stated that the department had not recouped the noncompliant payments or reimbursed the federal government for those costs. Missouri also paid 56 claims totaling $5,170 for drugs excluded from Medicaid coverage in the fourth quarter of 2016, reflecting a manual process for turning off NDCs that could miss excluded drugs. [Report 80]
Maryland’s Office of Legislative Audits found approximately $397,000 in overpayments on 11 of 15 manually processed Maryland Medicaid Pharmacy Program claims tested. The audit also found that the Department of Health lacked procedures to verify prescriber licensure before pharmacy claims were paid. [Report 83]
The Maryland audit further found that three of four fee-for-service pharmacy programs’ claims were not audited, reversals were not analyzed, and available drug-utilization data were not used to identify improper claims. This is particularly consequential because reversal patterns and utilization data can direct auditors toward exceptions that conventional payment edits do not detect. [Report 83]
Together, these findings show that PBM and pharmacy oversight must test both automated controls before payment and targeted analytics after payment.
This is a single-report Texas theme with five findings; it should not be treated as a cross-state PBM pattern. Still, it matters because PBM pharmacy-cost data can influence capitation rates, and procurement controls affect who administers critical pharmacy functions.
The Texas rate-setting audit found that required procurement certifications and disclosures were not consistently completed. Five of 13 required nepotism forms were missing before contract award, and three of 12 required nondisclosure and conflict-of-interest certifications were not obtained before vendor proposals or evaluation activity. [Report 114]
The same audit found incomplete disclosure of rate methodology and analysis to oversight entities, including limited explanation of rounding methodologies and the relevance of Data Analysis Unit analyses. [Report 114]
This is a narrower governance warning: when the agency cannot demonstrate independent procurement decision-making or clearly explain how reconciled data affected rates, confidence in PBM-related financial oversight weakens.
The recurring weakness is fragmented accountability across handoffs. PBM oversight may be assigned to a managed-care contract unit, while encounter data sit with claims operations, financial reconciliations with an MCO oversight unit, rebate processing with a contractor, and rate-setting effects with actuarial staff. The audits show that each handoff can lose information: returned funds are omitted from encounter data, rejected encounters are not corrected, rebate-eligible claims are not extracted, or reconciliations are completed too late to influence rates. [Report 7] [Report 114] [Report 115]
Pricing transparency and data integrity are therefore inseparable. A requirement to prohibit spread pricing or disclose fees has limited value if the agency cannot trace individual claims to pharmacy remittance advice, adjustments, and final payment. Conversely, a technically complete encounter file is not enough if contract terms permit non-Medicaid aggregation that prevents Medicaid-specific attribution of returned funds or fees. [Report 7] [Report 65]
The most consequential findings also show that oversight should not stop at aggregate performance metrics. Pennsylvania specifically recommended testing whether individual PBM-processed claims were accurate based on prescriptions, pharmacy remittance advices, and adjustment documentation—not only whether aggregate timeliness and accuracy benchmarks were met. Maryland’s reversal and utilization-data findings point to the same conclusion: exception analytics must lead to documented investigation and recovery activity. [Report 65] [Report 83]
Finally, third-party oversight is not a technical sidebar. PBMs, fiscal agents, rebate contractors, and system vendors can all influence the accuracy or availability of pharmacy and financial data. Independent assurance, defined exception reporting, timely remediation, and documented agency review are necessary to make contractual rights enforceable in practice. [Report 86] [Report 115]
The financial evidence is meaningful but incomplete and should not be collapsed into a single headline total. Amounts fall into different categories—identified improper payments, uncollected rebates, and program or transaction values reviewed—and some New York rebate figures may overlap.
Identified improper payments. Missouri and Maryland findings within the pharmacy-payment-integrity theme identified $572,170 in improper payments: approximately $170,000 in Missouri physician-administered drug claims paid without NDCs in 2016; $5,170 for 56 excluded-drug claims paid in Missouri in the fourth quarter of 2016; and approximately $397,000 in Maryland overpayments involving 11 of 15 manually processed claims tested. The Maryland figure is test-based and should not be generalized beyond the population tested. [Report 80] [Report 83]
Uncollected rebates. New York reported $183.7 million in uncollected Medicaid drug rebates during its audit period. This is the largest identified amount in the corpus and was associated with material-weakness severity. The report also identified component missed-rebate figures, including approximately $119 million from extraction errors, approximately $109.4 million associated with zero-dollar-paid data, $12.8 million for previously omitted Medicaid-only PACE claims, about $6.4 million for claims rejected or not reported during a contractor transition, and $993,207 tied to same-quarter reversals. These component amounts are not added to the $183.7 million audit-period total because the evidence does not establish whether they overlap. [Report 115]
Payments reviewed or reported—not loss. Texas reported $26.4 million in fiscal year 2018 STAR Kids pharmacy expenses that did not reflect final amounts paid to pharmacies; this is an expense-reporting population, not an identified improper-payment amount. Separately, the 1,297 unreported compound-drug encounters totaled $132,511, also a reported transaction value rather than a finding of loss. Missouri’s approximately $959 million in 2016 outpatient prescription-drug payments provides program-scale context only. [Report 7] [Report 80]
Severity fields reinforce the prioritization but are not a substitute for dollar evidence. PBM pricing-transparency findings ranged from deficiency to material noncompliance; rebate and information-security themes included findings rated material weakness. Sparse financial fields mean that unquantified findings—especially those involving transparency, contracts, and data integrity—should not be treated as low-risk merely because no dollar amount was extracted. [Report 65] [Report 86] [Report 115]
The following work program is prioritized by potential effect on payment accuracy, transparency, recovery, and rate-setting reliability. All procedures below are recommended by the source audits, not newly asserted facts.
- Trace PBM-adjudicated claims from prescription through final payment.
Objective: Verify that encounter data, pharmacy remittances, adjustments, returned funds, and final disposition in the Medicaid claims system agree at the claim level.
Key controls/tests: Select a risk-based sample emphasizing adjusted claims, compound drugs, high-cost drugs, reversals, and claims with PBM fees. Trace each sample item to prescription support, pharmacy remittance advice, adjustment documentation, MCO/PBM encounter submission, and final system disposition. Reconcile differences and test correction and resubmission of rejected encounters.
Expected evidence: Claim-detail extracts, prescription records, remittance advices, adjustment and reversal files, encounter submissions, rejection reports, correction logs, and final adjudication records.
Provenance: Recommended by the source audits. Addresses pricing transparency and encounter-data risks identified in Texas and Pennsylvania. [Report 7] [Report 65] - Review every new or amended MCO-PBM subcontract before it becomes effective.
Objective: Ensure PBM contracts incorporate Medicaid requirements and give the agency enforceable access to pricing, adjustment, and compliance information.
Key controls/tests: Compare all executed and amended subcontracts to a standardized compliance checklist; confirm inclusion of required Medicaid provisions, disclosure obligations, audit rights, and enforcement terms. Test whether exceptions were escalated and resolved before implementation.
Expected evidence: Contract inventory, executed contracts and amendments, completed checklists, legal and program review sign-offs, exception logs, corrective-action correspondence, and enforcement records.
Provenance: Recommended by the source audits. Addresses the Pennsylvania finding that contract monitoring was ineffective. [Report 65] - Require complete PBM financial disclosures and independently audit high-risk activities annually.
Objective: Establish visibility over rebates, administrative and transmission fees, spread pricing, pharmacy adjustments, and final pharmacy payments.
Key controls/tests: Test the completeness and accuracy of periodic PBM disclosures against source claim, remittance, and financial records. Review whether independent annual audits cover defined high-risk activities and whether noncompliance triggers escalation.
Expected evidence: PBM transparency reports, fee schedules, rebate records, pharmacy reimbursement schedules, adjustment files, annual audit reports, management responses, and escalation documentation.
Provenance: Recommended by the source audits. Addresses Oregon’s findings on limited transparency, fragmented oversight, and insufficient contract provisions. [Report 100] - Reconcile the full rebate pipeline from source claim through collection.
Objective: Determine whether every rebate-eligible claim was extracted, accepted by the contractor, invoiced, recorded as a receivable, and collected or appropriately resolved.
Key controls/tests: Reconcile source claims to extraction files, contractor acceptance and rejection files, reversal files, invoice files, accounts receivable, and manufacturer receipts. Investigate omitted claims, rejected claims, zero-dollar-paid records, and aged receivables; test whether eligible claims were subsequently invoiced.
Expected evidence: Source-claim populations, extraction logic and output, contractor processing files, rejection queues, invoice detail, receivables aging, collection records, and recovery correspondence.
Provenance: Recommended by the source audits. Addresses New York’s extraction, transition, reversal, and collection weaknesses. [Report 115] - Test prepayment and postpayment pharmacy-payment integrity controls.
Objective: Determine whether manual claims, prescriber eligibility, excluded-drug rules, reversals, and utilization patterns are controlled before and after payment.
Key controls/tests: Independently review manually processed claims; verify prescribing-provider licensure before payment; audit each fee-for-service pharmacy program on a test basis; and analyze reversal rates and utilization anomalies for follow-up investigation.
Expected evidence: Manual-claim logs, reviewer approvals, provider-license verification results, pharmacy-claim audit workpapers, reversal analytics, utilization reports, investigation records, and recovery actions.
Provenance: Recommended by the source audits. Addresses Maryland’s manual-claim, licensing, audit-coverage, and utilization-surveillance findings. [Report 83] - Challenge NDC, procedure-code, drug-unit, and excluded-drug edits.
Objective: Verify that critical claims edits prevent payment of noncompliant claims and preserve data needed for rebate billing.
Key controls/tests: Use claims designed to fail NDC, procedure-code, drug-unit, unclassified-code, and excluded-drug validations. Identify paid exceptions, determine rebate eligibility, and test recoupment or recovery follow-up.
Expected evidence: Edit specifications, test scripts and results, claims-system configuration, paid-exception reports, NDC crosswalk-maintenance logs, recovery files, and rebate invoices.
Provenance: Recommended by the source audits. Addresses Missouri and New York findings on missing or invalid drug information and excluded-drug payment controls. [Report 80] [Report 115] - Test whether reconciled pharmacy financial information reaches rate-setting staff in time.
Objective: Confirm that AUP engagements and MCO financial reconciliations are completed, reviewed, communicated, and reflected before capitation rates are set.
Key controls/tests: Compare engagement completion dates, reconciliation dates, and rate-setting milestones. Trace selected reconciliation results to communications with actuarial staff and rate-setting documentation.
Expected evidence: AUP reports, FSRs, reconciliation workpapers, review approvals, actuarial communication records, rate-setting calendars, and methodology documentation.
Provenance: Recommended by the source audits. Addresses delayed and uncommunicated Texas reconciliations. [Report 114] - Obtain independent security and service-provider assurance over systems handling pharmacy data.
Objective: Assess whether claims, rebate, and financial data are supported by controlled system changes, access, configuration, vulnerability remediation, and third-party oversight.
Key controls/tests: Review information-security audits and service-organization control reports; test corrective-action closure, annual access reviews, database configuration baselines, vulnerability-remediation timeliness, and third-party monitoring.
Expected evidence: Security assessments, system and organization controls (SOC) reports, access-review attestations, change tickets, configuration-baseline reviews, vulnerability scans, remediation plans, and vendor oversight records.
Provenance: Recommended by the source audits. Addresses Virginia’s high-severity information-security, fiscal-agent, and third-party-risk findings. [Report 86]
- Can the agency trace a PBM-adjudicated claim from the prescription and pharmacy remittance advice through every adjustment, encounter submission, and final pharmacy payment—without relying solely on PBM-reported aggregates?
- Do MCO-PBM contracts require Medicaid-specific attribution of returned funds, fees, rebates, and adjustments, including when a PBM serves commercial and Medicaid lines of business?
- Which rejected encounters, reversals, or contractor exceptions have never been corrected, resubmitted, invoiced, or investigated?
- Has the agency reconciled its claims population to rebate invoices and collections recently enough to identify missed claims before recovery becomes difficult?
- Are manual pharmacy claims, prescriber licenses, excluded-drug edits, and NDC fields independently tested, or is the agency relying on control design without evidence of operating effectiveness?
- Can the actuarial function show exactly how late reconciliations, AUP results, PBM fees, or encounter-data corrections affected—or did not affect—managed-care rate setting?
- Do independent assurance reports cover the PBM, fiscal agent, rebate contractor, and other vendors that handle pharmacy claims and financial data? If not, what compensating agency testing exists?
- Who owns exception resolution across the MCO, PBM, pharmacy, claims-system, rebate-contractor, and Medicaid-agency boundaries—and what escalation occurs when that ownership fails?
This review draws on 10 of the 108 active reports in the database, covering Maryland, Missouri, New York, Oregon, Pennsylvania, Texas, and Virginia and published between December 2018 and December 2024. It includes 53 findings.
Scoped findings are not statistically representative of all Medicaid programs or all PBM arrangements. The corpus combines PBM-specific audits with broader pharmacy, managed-care, rebate, rate-setting, and information-technology reports; not every finding is exclusively attributable to PBM operations. Reports 6 and 26 contain substantially similar Texas managed-care oversight content, and the available evidence does not establish whether they reflect separate audit work or duplicated reporting. [Report 6] [Report 26]
Financial fields are sparse, and a redacted Maryland cybersecurity finding cannot support substantive assessment of the underlying condition. Most importantly, New York’s $183.7 million audit-period rebate figure is not combined with its component missed-rebate figures because overlap is not established. [Report 83] [Report 115]
Evidence register
Sources referenced
- Report ID
- REPORT 6
- Report ID
- REPORT 7
- Report ID
- REPORT 26
- Report ID
- REPORT 65
- Report ID
- REPORT 80
- Report ID
- REPORT 83
- Report ID
- REPORT 86
- Report ID
- REPORT 100
- Report ID
- REPORT 114
- Report ID
- REPORT 115