Audits
Navigating Medicaid & the AI Audit Bomb
5 ways to fight back from the risks posed by automated payment reviews
By Stephen Bittinger & Mattie Bowden
Artificial intelligence and advanced analytics are reshaping Medicaid audits, payment reviews and prior authorization, and these cutting-edge issues are being litigated nationally. Before public litigation, the fight begins at the administrative and contractual audit level when AI and algorithmic tools have reshaped the landscape of claims review and submission—heightening the risk of a misstep in traditionally mundane processes.
Medicaid Is Ground Zero
Medicaid is the central payer financing homecare, covering approximately 40% of all home health expenditures and the vast majority of homecare spending for elderly and disabled Americans when broader long-term services and supports are included. When the government deploys AI to audit Medicaid homecare billing, the practical reach of that technology is nearly universal.
Algorithms are now flagging claims before a human ever sees them, automated edits are blocking payments in real time and predictive analytics are sorting providers into risk tiers before an investigator is ever assigned. For Medicaid-dependent agencies, a change in audit technology can quickly become an existential threat.
The government’s urgency is understandable. The Centers for Medicare & Medicaid Services (CMS) reported a 6.12% Medicaid improper payment rate for fiscal year 2025, or an estimated $37.39 billion. However, 77.17% of those improper payments resulted from insufficient documentation and were generally not indicative of fraud or abuse. AI is undoubtedly far more capable of finding documentation failures across hundreds of millions of claims than traditional human auditors. But when a model trained on imperfect data flags a compliant provider, no one is waiting for a human reviewer to catch the error before the recoupment demand goes out. This pattern has increased over the past few years with more agencies and contractors using AI tools.
When Automation Becomes an Adverse Action
Managed care now dominates Medicaid. As of July 2024, 78% of beneficiaries were enrolled in comprehensive risk-based managed care organizations. That market structure matters because capitation creates real financial pressure to control utilization, but it does not authorize denial of covered care. Federal Medicaid rules still require that authorization criteria be applied consistently, that clinical expertise be brought to bear, that adverse decisions come with actual reasons and that enrollees have access to the records and coverage standards driving those decisions. In practice, those requirements are often the first point of leverage. A plan has to connect its automated output to governing rules, clinical judgment and a rationale someone can review and challenge.
The risk runs in both directions. On the provider side, billing, coding and documentation tools shape what ends up on a claim, and that has False Claims Act implications worth taking seriously. Importantly, a software recommendation is not itself liability, but it is not a safe harbor either.
In United States ex rel. Schieber v. Holy Redeemer Healthcare System, Inc., the suit alleged that Homecare Homebase software prompted users to inflate planned therapy visits near reimbursement thresholds. The court allowed certain theories to survive the pleading stage without reaching liability. The practical lesson is the point: Human review has to be genuinely independent, informed, documented and actually capable of overriding the tool.
The Black Box Problem
CMS’s Transformed Medicaid Statistical Information System (T-MSIS) infrastructure, state electronic visit verification systems and payer data warehouses make large-scale comparison possible. Yet Medicaid remains a collection of state, district and territorial programs with different coverage, authorization, documentation and appeal rules.
Federal reviews have found that Medicaid data quality has improved but remains uneven. A model can therefore be internally consistent and still apply the wrong state rule, rely on incomplete fields or treat an unusual but legitimate practice pattern as suspicious.
An outlier score is a lead, not a legal conclusion. Litigators are working to turn the black box into a reviewable record: the model or edit version, inputs, thresholds, state-specific rules, validation materials, manual changes and the reason an output became an adverse action. Source code may not be necessary in every matter, but a provider cannot meaningfully answer a major demand supported only by the phrase “data analytics.”
Fighting Back
Providers facing AI-generated overpayment demands, payment suspensions and automated denials likely have more legal tools than they often realize.
This is an actively developing area of litigation and the law is catching up. Some options include:
1. State Administrative Procedure Act Challenges
Most state Medicaid recoupment actions are subject to administrative review under state administrative procedure acts. The core standard—whether an agency’s action was arbitrary and capricious—provides meaningful grounds to challenge an audit when the underlying methodology is opaque, inadequately disclosed or invalidated for the claims at issue.
2. Constitutional Due Process
The Supreme Court’s framework in Mathews v. Eldridge requires weighing the private interest at stake, the risk of erroneous deprivation and the government’s administrative burden. A homecare agency facing a six-figure recoupment demand has a substantial protected property interest. The risk of erroneous deprivation is elevated when the finding was generated by a model that auditors themselves cannot fully explain. That imbalance supports a due process argument that current notice and hearing procedures are constitutionally inadequate given the opacity of the tools driving the audit findings.
3. Payment Suspension Challenges
When a state Medicaid agency suspends payments pending a fraud investigation, federal regulations provide specific rebuttal rights. Under 42 C.F.R. § 455.23, a provider may submit information demonstrating that there is no credible allegation of fraud, that the allegation is without merit or that good cause exists to lift the suspension. A credible allegation arising solely from an algorithmic flag, without independent corroboration, presents a legitimate argument that the suspension threshold has not been met. Those challenges must move quickly—a payment suspension can be immediately catastrophic for agencies operating on thin margins and acting early preserves options that are unavailable later.
For Medicaid-dependent agencies, a change in audit technology can quickly become an existential threat.
4. MCO Denial Appeals
When a Medicaid managed care organization (MCO) denies a claim using an AI utilization management tool, federal regulations establish a layered appeals framework of internal MCO appeals, external independent review and state fair hearings. If the MCO cannot or will not disclose the algorithm’s clinical reasoning for the denial, that itself may violate the regulatory requirement to provide a clear explanation of the denial basis. CMS’s 2024 guidance requiring individualized clinical review creates a direct hook: A denial that cannot be explained in clinical terms was not made on a proper basis, and that is an argument for reversal at every level of the appeals process.
5. Statistical Sampling Challenges
Many AI-driven audits use statistical sampling to extrapolate overpayment amounts across a universe of claims far larger than the sample reviewed. That methodology must satisfy specific technical standards, such as unbiased sampling, proper stratification, validated sampling design and defensible extrapolation assumptions. Errors in sampling design can invalidate the extrapolated demand entirely.
These matters rarely fit into a single legal silo. They may require emergency suspension work, administrative appeals, managed care strategy, False Claims Act analysis, vendor-contract review and statistical testing at the same time.
The Bottom Line
AI-assisted Medicaid oversight is not going away. The strongest response is not simply, “The algorithm is wrong.” Rather, it is an evidence-based reveal of what data was used, what rule governed, how the methodology operated, who made the decision, where the process failed and what remedy the law provides. The algorithm does not know your patients. We help make sure the record, the methodology and the law tell the full story.

Stephen Bittinger is a Polsinelli shareholder and co-chair of the firm’s APA Practice Group. His practice focuses on healthcare reimbursement, audits, statistical sampling, analytics and algorithmic evidence.

Mattie Bowden represents healthcare providers in reimbursement, denial, recoupment and administrative appeals and managed care disputes. Together, they advise and defend homecare organizations confronting AI-assisted audits and payment disputes. Visit polsinelli.com.
Dmytro - adobestock.com
ISSUES YOU MAY HAVE MISSED


