NORMAN SPENCER LAW GROUP

  • Home
  • About
    • Attorney Profiles
    • Consultation And Fees
  • Practice Areas
    • Practice Areas
    • Criminal Defense
      • Healthcare Fraud
      • Tax Fraud
      • Medicaid Fraud
      • Financial Crime
      • Sex Crimes
      • Theft Crimes
        • Shoplifting
      • International Criminal Law
      • Money Laundering & Immigration Violations
      • Cyber Crimes
    • Professional License Defense
      • CPAs
      • OPMC Physicians Defense
      • OPD Lawyer
      • Dentist Defense
      • Nursing License Defense
      • Nurse Practitioners License Defense
      • Optometrists
      • Pharmacists
      • Physical Therapists
      • Physician Assistant (PA)
      • Psychologists
      • Social Workers
      • Medical Spas
    • Government Investigation
      • Securities and Exchange
      • OIG Health Care Investigation Lawyer
      • DEA Investigations
      • Medicaid Fraud Control Unit
      • OMIG Defense Attorneys
      • NYC Department of Investigations
      • NYC Department of Health
      • Subpoenas
    • Healthcare Compliance
  • Case Results
  • Blog
  • Contact Us
Call Today: (212) 577-6677

New York Medicaid Managed Care Audits: Why Providers Are Being Reviewed More Closely

By Norman Spencer August 4, 2026

A Medicaid managed care audit in New York may start with a health plan’s Special Investigation Unit, an outside audit vendor, or the New York State Office of the Medicaid Inspector General. The letter may ask for medical files, orders, service logs, billing support, employee information, or records tied to a defined group of claims.

The increase in scrutiny is not random. New York requires Medicaid managed care organisations to run fraud, waste, and abuse prevention programs, conduct provider audits and investigations, review supporting records, and report investigative activity to state agencies. OMIG’s 2026 Work Plan also states that the agency has begun, and plans to expand, audits that review fee-for-service claims and managed care encounters in the same engagement.

For providers, this creates a wider review system. A claim may be examined by the managed care plan that paid it, by a contractor acting for that plan, or by OMIG using encounter data reported to the state. A routine payment review may stay administrative. A case involving suspected false records, services not rendered, excluded individuals, or intentional billing conduct may move into a more serious investigation.

What Is a Medicaid Managed Care Audit in New York?

A Medicaid managed care audit in New York is a review of claims, services, records, billing practices, or provider operations connected to care paid through a Medicaid managed care organisation, often called an MMCO or MCO.

The provider usually bills the plan rather than submitting the claim through Medicaid fee-for-service. The plan pays or denies the claim, then reports encounter information to New York. That encounter information gives state reviewers a separate data source for testing whether payment activity matches Medicaid rules, plan contract duties, other insurance information, and the provider’s records. OMIG’s current work plan expressly refers to reviews of Medicaid managed care encounters alongside fee-for-service claims.

The phrase “managed care audit” may describe several different proceedings. That difference matters because the authority, deadline, requested records, appeal route, and financial risk may change depending on who sent the letter.

Who May Review a Medicaid Managed Care Provider?

  • The managed care plan: A plan may use its compliance staff or Special Investigation Unit to review provider claims, medical records, orders, utilisation, and payment patterns.
  • A plan contractor: New York guidance permits MMCOs to delegate some Special Investigation Unit work. An audit company, payment integrity vendor, or other subcontractor may send the records request.
  • OMIG: OMIG audits providers and managed care organisations. It may review managed care encounter data, provider records, billing support, overpayments, or a plan’s performance under its state contract.
  • A Recovery Audit Contractor: OMIG works with a Recovery Audit Contractor on payment reviews. The 2026 Work Plan states that certain projects will use Medicaid and Medicare data to identify duplicate payments and incorrect patient liability amounts involving dual-eligible recipients.
  • The Medicaid Fraud Control Unit (MFCU is not the routine payer conducting a contract audit. It may become involved when suspected criminal activity is referred for law enforcement review. OMIG guidance directs MMCOs to report reasonably suspected criminal activity to OMIG and MFCU.

Why Are New York Medicaid Providers Being Reviewed More Closely?

Several parts of New York’s program integrity system now push managed care plans toward active provider oversight. The result is more data review, more record requests, and more reporting about provider investigations.

New York Requires Managed Care Plans to Run Active Audit Programs

Under 18 NYCRR SubPart 521-2, Medicaid managed care organisations must maintain policies and procedures designed to detect and prevent fraud, waste, and abuse. Their agreements with participating providers, contractors, agents, and subcontractors must state that those parties are subject to audit, investigation, or review under the plan’s prevention program.

Plans with an enrolled population of at least 1,000 during a calendar year must establish a full-time Special Investigation Unit. The SIU must prepare an annual work plan that identifies provider names or provider types for planned audits or investigations, the intended scope, the review period, and the reason for the project.

New York guidance also states that MMCO audits, investigations, and reviews must involve at least one per cent of the aggregate Medicaid claims paid. Those projects may include prepayment or post-payment review of claims, medical records, orders, and other documents used to support billing.

That requirement helps explain why a provider with no prior enforcement history may still receive an audit letter. Plans are expected to identify risk areas and conduct review work. A provider may be selected because of a billing pattern, provider category, complaint, data match, annual SIU project, or random sample within a broader audit.

Plans Must Report Provider Investigations and Recoveries

Managed care plans do not keep all provider review activity inside the company. Current OMIG instructions require mainstream managed care plans, special needs plans, and Health and Recovery Plans to submit Provider Investigative Reports each month. Those reports cover investigative, educational, and re-educational activity, as well as overpayments recovered. Plans must also submit Medicaid-related settlement agreements.

OMIG’s current program integrity matrix assesses whether plans submit 12 timely Provider Investigative Reports during each calendar year, whether the reports contain required certifications, and whether the information and settlement agreements are complete and accurate.

This reporting structure gives plans a reason to document their audit work carefully. It also means a provider dispute that begins with a plan may become visible to OMIG through required reporting.

OMIG Reviews Whether Plans Are Policing Their Networks

OMIG conducts Medicaid Managed Care Program Integrity Reviews to test whether an MCO is meeting program integrity duties in its state contract. The review looks at such areas as exclusion screening, provider managing-employee checks, compliance programs, SIU operations, service verification, overpayment procedures, potential fraud reporting, and Provider Investigative Reports.

An MCO selected for this review receives an audit notification and a review module. OMIG states that the plan generally has 35 days to submit the completed module and supporting material. A plan that fails to meet its program integrity duties may face recovery of up to two per cent of the administrative component of its Medicaid premium for the review period.

This oversight places the plan’s own provider-audit activity under review. In practical terms, an MMCO may need to show that it screened providers, verified services, investigated risk, collected overpayments, and reported concerns as required.

OMIG Is Combining Fee-for-Service and Managed Care Review

OMIG’s 2026 Work Plan states that the agency has started, and will expand, provider audits that review fee-for-service claims and managed care encounters in one audit engagement. OMIG said this approach is meant to test compliance across both payment channels without opening separate audits.

A provider that bills both systems should not assume the managed care side will stay separate from fee-for-service activity. A pattern found in one payment stream may lead reviewers to compare dates, recipients, codes, orders, locations, or payer information across both.

The same work plan identifies system-match reviews involving clinic, emergency room, laboratory, and ordered ambulatory services billed during an inpatient hospital stay. It also describes reviews using Medicare and Medicaid information to find duplicate primary-payer payments or inaccurate patient responsibility amounts for people enrolled in both programs.

Plans Must Report Potential Fraud, Waste, and Abuse

New York guidance requires MMCOs and their subcontractors to report potential fraud, waste, and abuse to OMIG. Before reporting, the plan is expected to take reasonable steps to determine whether the allegation or complaint may be supported, which may include data review, medical-record review, or other investigative work.

The guidance draws a separate line for reasonably suspected criminal activity. Such matters are reported to OMIG and MFCU through a different process.

This distinction is important. A payment error, weak record, or coding dispute is not automatically managed care fraud. Still, a provider’s response may affect how the plan classifies the matter. An incomplete explanation, inconsistent production, altered file, or unsupported assertion may deepen concern rather than resolve it.

What May Trigger an MMCO Audit?

Plans and OMIG do not publish every selection method. Their public materials do show the kinds of issues that program integrity work is built to detect.

  • Unusual billing patterns: A provider’s units, frequency, codes, patient volume, or payment activity may differ from peers or prior billing.
  • Duplicate or overlapping payments: Reviewers may compare Medicaid managed care encounters, fee-for-service claims, Medicare payments, and other insurance data.
  • Services during an inpatient stay: Certain clinic, emergency room, laboratory, or ambulatory claims may conflict with a bundled inpatient payment.
  • Excluded individuals or entities: Plans must screen participating and nonparticipating providers, employees, and certain managing personnel against state and federal exclusion data.
  • Service-verification concerns: OMIG tests whether MCOs use a statistically valid process to verify that billed services were delivered to members.
  • A complaint or referral: Member complaints, employee reports, another agency’s referral, or a plan’s internal review may start the process.
  • An overpayment pattern: Repeated credit balances, voids, adjustments, payer-order issues, or delayed repayment may draw added review.
  • Missing or inconsistent provider records: Claims that lack supporting orders, signatures, service detail, or reliable time records may be questioned even when care was provided.

Selection for review does not prove wrongdoing. It means the payer or agency wants support for payment, compliance, or service delivery.

What Provider Records May Be Requested?

The scope depends on the provider type, contract, claims at issue, and audit objective. New York guidance expressly refers to claims, medical records, orders, and other supporting documents. The managed care review matrix also covers exclusion checks, service verification, overpayment procedures, investigative files, and provider reporting.

A request may seek:

  • Clinical records: Progress entries, assessments, plans of care, medication information, test results, discharge material, and records showing what service was delivered.
  • Orders and authorisations: Referrals, prescriptions, physician orders, prior authorisation records, and renewals applicable to the billed service.
  • Service records: Visit logs, attendance records, transportation records, time entries, electronic visit verification data, or other proof tied to the provider category.
  • Billing material: Claim files, remittance data, adjustment history, voids, credit balances, explanations of benefits, and proof that another insurer was billed first when required.
  • Staff and credential files: Licenses, certifications, enrollment information, ownership information, managing-employee data, exclusion checks, and work schedules.
  • Contracts and vendor files: Agreements with billing companies, staffing companies, transportation brokers, management companies, or other parties involved in Medicaid services.
  • Compliance material: Policies, training records, internal reports, investigation material, and corrective action documents relevant to the audit period.

A provider should read the demand line by line. Producing an unreviewed data dump may expose material outside the stated scope, create inconsistent answers, or disclose privileged legal communications.

Why Documentation Problems Create Audit Risk

Medicaid payment usually depends on more than proof that a patient appeared at the office or received some care. The record must support the billed service under the rules in effect on the service date.

Common audit disputes include:

  • The record does not support the code billed: The service description, duration, complexity, or provider type may not match the claim.
  • The order was missing or expired: A service may have been useful, yet still fail a payment rule tied to a valid order or authorisation.
  • Dates and times conflict: A time entry may overlap with another patient, another employer, an inpatient stay, travel time, or a different service.
  • The signer was not identifiable: Initials, unsigned entries, or unclear credentials may make it difficult to establish who performed or supervised the service.
  • Template text replaced patient-specific detail: Repeated wording may make reviewers question whether the record reflects the actual encounter.
  • The record was created or changed after the request: Late entries may be permissible in limited settings when properly identified, but silent alteration can create serious credibility and fraud concerns.

The safest approach is to preserve the file as it existed, identify any legitimate late entry under the applicable record policy, and provide a truthful explanation rather than trying to make an old record look cleaner.

Does a Managed Care Audit Mean the Provider Is Accused of Fraud?

No. A Medicaid managed care audit in New York may be a routine post-payment review, service-verification project, data match, contract audit, compliance check, or inquiry into a small claim sample.

OMIG publicly reports audits that close with no further provider action. In those matters, the agency issues an Audit Summation Letter stating that the provider generally complied with the requirements reviewed.

Fraud usually raises a different issue, whether the evidence suggests knowing deception or intentional false billing rather than an isolated mistake. Managed care fraud concerns may become more serious when records appear fabricated, services were not rendered, excluded persons were used, kickbacks affected referrals, or false explanations were given during the review.

Providers should avoid both extremes. Panic can lead to careless statements. Dismissing the letter as routine can lead to a missed deadline or incomplete production.

What Can Happen After a Managed Care Audit?

The result depends on who conducted the review and what the records show.

A plan may uphold payment, request more information, deny claims, seek repayment, place claims under prepayment review, impose a corrective action plan, or take action under the provider agreement. OMIG may close the audit, issue draft findings, seek recovery, or pursue an administrative process.

When a plan identifies potential fraud, waste, or abuse, New York rules may require reporting to OMIG. When the facts support reasonably suspected criminal activity, the matter may be reported to OMIG and MFCU.

An audit may also reveal an overpayment that the provider has a duty to report, return, and explain. New York’s managed care guidance requires MMCOs to maintain a process through which providers report and return identified overpayments within the applicable 60-day period, and the plan must publish instructions on its website.

The correct repayment route may depend on how the payment was made, whether a review has already started, and whether the issue affects other claims. A provider should assess the full claim set before making a narrow repayment that leaves the same issue unresolved elsewhere.

How Should a Provider Respond to an Audit Letter?

A strong response begins with control, accuracy, and a clear understanding of the proceeding.

  • Identify the sender: Confirm whether the request came from the plan, its SIU, an outside vendor, OMIG, a Recovery Audit Contractor, or law enforcement.
  • Calendar every deadline: Record the response date, extension rules, meeting dates, and any deadline for objections or appeal.
  • Preserve records: Suspend routine destruction for files, emails, billing data, text messages, logs, and other material tied to the review.
  • Define the claim set: Obtain the claim list, audit period, provider numbers, members, codes, and stated audit objective.
  • Review the governing rules: Check the provider agreement, plan manual, Medicaid policy, OMIG protocol, and service-date rules that apply to the claims.
  • Compare claims with records: Test whether each claim is supported by the clinical file, order, authorisation, staff credential, service log, and payment information.
  • Track missing material: Identify records held by laboratories, hospitals, ordering providers, vendors, former employees, or storage services, then document retrieval efforts.
  • Keep original files intact: Do not silently edit, recreate, backdate, or replace records. Any lawful late entry should be clearly identified and handled under the applicable policy.
  • Control communications: Use one response team so the plan does not receive conflicting explanations from billing staff, clinicians, managers, and owners.
  • Review repayment duties: Determine whether an identified overpayment requires repayment to the plan, disclosure to OMIG, or a wider internal claim review.
  • Submit a focused production: Organise records by claim or request item, include a clear index, and explain genuine gaps without speculation.
  • Respond to draft findings: Preserve every factual and legal objection in writing and attach the records that support the position.

For certain OMIG audits, a provider generally has 30 days to respond to a Draft Audit Report, subject to the governing rule and any granted extension. A provider may request an administrative hearing within 60 days of a Final Audit Report. The exact notice controls.

How Far Back Can OMIG Review Claims?

OMIG states that its audits are generally limited to services furnished or billed within the six years before the agency’s written notice of intent to audit. A longer period may be reviewed when fraud is involved. OMIG also states that it must begin the audit within 60 days after the notice, or within 120 days when it gives a later written notice.

A plan request may cite its provider agreement, plan manual, state contract, or another retention rule. Providers should not assume that every review uses the same date range. The letter and governing authority should be checked before objecting to scope or deciding which files are responsive.

How Medicaid Compliance Can Reduce Managed Care Audit Risk

Audit preparation is stronger when it happens before a records request.

  • Run claim samples: Compare selected claims with the full supporting file, not just the billing screen.
  • Test payer order: Confirm that Medicare or other insurance was billed before Medicaid when required.
  • Review encounter consistency: Check whether managed care claims, fee-for-service claims, authorisations, and patient status tell the same story.
  • Screen excluded parties: Verify the required state and federal checks for employees, contractors, owners, and managing personnel.
  • Audit vendors: Review the work of billing companies, staffing vendors, and other contractors rather than assuming their systems are accurate.
  • Track overpayments: Use a written process for investigating, quantifying, reporting, and returning payment errors within the required period.
  • Train by job duty: Clinicians, billers, schedulers, managers, and owners face different risks and need role-specific instruction.
  • Test record access: Make sure records can be retrieved after staff turnover, office closure, software changes, or vendor disputes.

Good Medicaid compliance does not mean creating more paperwork for its own sake. It means making sure the claim, the record, the staff file, and the payment history agree.

Frequently Asked Questions About MMCO Audits

Can a Medicaid Plan Audit a Participating Provider?

Yes. New York guidance requires MMCO agreements with participating providers and other contractors to state that they are subject to audit, investigation, or review under the plan’s fraud, waste, and abuse prevention program.

Are MMCO Audits Limited to Suspected Fraud?

No. Plans may conduct prepayment review, post-payment review, service verification, utilisation review, overpayment work, or other payment integrity projects. New York guidance requires plan audit and investigation activity across at least one per cent of aggregate Medicaid claims paid.

Does OMIG Review Managed Care Claims?

OMIG reviews Medicaid managed care encounter data and has stated that it is expanding provider audits that examine fee-for-service claims and managed care encounters in the same engagement.

Will the Plan Report an Audit to OMIG?

The answer depends on the activity and findings. Plans must submit monthly Provider Investigative Reports describing Medicaid provider investigative, educational, and re-educational activity and recovered overpayments. Potential fraud, waste, and abuse may also require a separate report to OMIG.

Should a Provider Repay Immediately After Finding an Error?

The provider should act within the applicable deadline, but first determine the amount, affected claim set, payment source, and proper reporting route. New York requires a process for reporting and returning identified managed care overpayments, generally within 60 days after identification.

What Should a Provider Do When Records Are Missing?

The provider should preserve what remains, identify where the missing material may be held, document retrieval efforts, and give a truthful explanation. Recreating or silently changing records after an audit request may create far greater risk than an openly explained gap.

Speak With a New York OMIG and Healthcare Audit Attorney

A Medicaid managed care audit in New York may begin as a claim review and expand into a dispute over repayment, provider records, network status, OMIG reporting, or suspected managed care fraud. Early review helps a provider understand the audit authority, protect original records, define the claim set, and prepare a consistent response.

Norman Spencer Law Group PC represents healthcare providers and businesses in OMIG audits, Medicaid investigations, healthcare fraud matters, and related government inquiries. The firm’s New York City office can review an audit letter, assess the requested provider records, respond to findings, and address related compliance or enforcement concerns.

This material is for general information and is not legal advice for any individual matter.

Filed Under: Healthcare Law

About Norman Spencer

Norman Spencer, Esq. is a New York City attorney and founder of Norman Spencer Law Group PC. He represents individuals and businesses in state and federal criminal matters, including white collar allegations, government investigations, licensing and professional discipline matters, and cases involving healthcare-related fraud. Norman earned his law degree from The Ohio State University and has represented clients in matters at various stages of investigation and prosecution, including grand jury proceedings, administrative actions, and forfeiture cases. He focuses on careful preparation, clear client communication, and strategic advocacy throughout the legal process.

Primary Sidebar

Recent Posts

  • New York Medicaid Managed Care Audits: Why Providers Are Being Reviewed More Closely
  • OMIG Self-Disclosure in New York: When Should a Provider Consider It?
  • What Happens When a New York Provider Gets an OMIG Education Letter?
  • Medicaid Billing for Deceased, Hospitalized, or Incarcerated Patients in New York
  • Medicaid Transportation Fraud New York: Why Transportation Companies Are Facing More Scrutiny

Categories

  • Compliance
  • Corporate Compliance
  • Criminal Law
  • Fraud
  • Government Investigation
  • Healthcare Law
  • RICO
  • Tax Law
  • Uncategorized
Norman Spencer Law Group Criminal Defense & Government Investigations Attorneys Contact Headshot

Request a consultation

This field is for validation purposes and should be left unchanged.

* fields are required

52 Duane St, New York, NY 10007

SITEMAP      PRIVACY POLICY

© COPYRIGHT 2026 Norman Spencer Law Group PC. ALL RIGHTS RESERVED

Email: ns@normanspencerlaw.com
Contact us: 24/7 (212) 577-6677
Fax: (212) 227-5602

Norman Spencer Law Group PC is a multi-practice law firm, providing Criminal Defense, Professional License Defense and Government Investigations Defense. This is an Attorney Advertisement and the information on this New York Criminal Defense Attorneys / Law Firm website is for general information purposes only. Nothing on this or associated pages, documents, comments, answers, emails, or other communications should be taken as legal advice for any individual case or situation. This information on this website is not intended to create, and receipt or viewing of this information does not constitute, an attorney-client relationship.
Designed, Developed and SEO by Attorney Marketing

  • Home
  • About
    • Attorney Profiles
    • Consultation And Fees
  • Practice Areas
    • Practice Areas
    • Criminal Defense
      • Healthcare Fraud
      • Tax Fraud
      • Medicaid Fraud
      • Financial Crime
      • Sex Crimes
      • Theft Crimes
        • Shoplifting
      • International Criminal Law
      • Money Laundering & Immigration Violations
      • Cyber Crimes
    • Professional License Defense
      • CPAs
      • OPMC Physicians Defense
      • OPD Lawyer
      • Dentist Defense
      • Nursing License Defense
      • Nurse Practitioners License Defense
      • Optometrists
      • Pharmacists
      • Physical Therapists
      • Physician Assistant (PA)
      • Psychologists
      • Social Workers
      • Medical Spas
    • Government Investigation
      • Securities and Exchange
      • OIG Health Care Investigation Lawyer
      • DEA Investigations
      • Medicaid Fraud Control Unit
      • OMIG Defense Attorneys
      • NYC Department of Investigations
      • NYC Department of Health
      • Subpoenas
    • Healthcare Compliance
  • Case Results
  • Blog
  • Contact Us