In February 2026, the U.S. Department of Health and Human Services Office of Inspector General (OIG) released new Industry Segment-Specific Compliance Program Guidance (Guidance) for Medicare Advantage Organizations (MAOs). While the guidance is not legally binding, it provides a detailed roadmap for managing compliance risks and strengthening oversight across Medicare Advantage operations.
The guidance is designed to supplement both Centers for Medicare & Medicaid Services (CMS) regulatory requirements and OIG’s broader General Compliance Program Guidance. It identifies seven risk areas that OIG believes deserve heightened attention from MAOs and offers practical recommendations to help organizations prevent, detect, and address compliance issues.
1. Prioritize Access to Care
Patients must have meaningful access to medically necessary services. Determining whether a service is medically necessary must be based on an individual patient’s circumstance, rather than relying solely on automated algorithms of software tools. MAOs should focus on maintaining adequate provider networks and ensuring provider directories are accurate and current, which may include quarterly updates. As part of access to care initiatives, MAOs should evaluate whether utilization management tools, including prior authorization, create barriers to care.
2. Monitor Marketing and Enrollment Agents
The guidance highlights significant risks associated with third-party marketers, brokers, and enrollment agents. MAOs should closely oversee delegated marketing activities, review compensation arrangements, and ensure incentives do not encourage enrollment in plans that may not be in a beneficiary’s best interest. OIG also reminds organizations that they remain responsible for marketing materials produced by subcontractors and should actively monitor for deceptive practices. Beneficiary complaints and unusual enrollment patterns are red flags worthy of investigation.
3. Focus on Risk Adjustment
OIG is concerned about diagnosis codes that cannot be verified or are not supported by patient encounters, which can lead to inflated risk scores and increased payments. Recommended controls include targeted reviews of high-risk diagnosis codes, oversight of chart review and in-home assessment programs, provider and coder education, data analytics, and implementation of corrective action when inaccuracies are identified.
4. Measure Assessments of Quality of Care
The guidance encourages MAOs to ensure that quality assessment data is “unbiased, accurate, and complete.” MAOs should also evaluate whether all enrollees have equitable access to care regardless of demographic characteristics. OIG additionally recommends robust provider oversight processes to ensure payments are made only to eligible providers. MAOs should take care to promptly remove excluded or suspended providers from networks. MAOs may consider requiring some or all network providers to be enrolled in Medicare as a compliance mechanism.
5. Oversee Third Parties
Many Medicare Advantage functions rely on First Tier, Downstream, and Related Entities (FDRs). However, MAOs may not delegate compliance administrative functions, and MAOs should take care to set processes in place to clearly categorize entities as FDRs. MAOs should conduct due diligence on vendors and partners, assess compliance programs, and perform risk-based monitoring. MAOs may consider incorporating contract provisions that require reporting, training, and self-audits. MAOs should be aware that FDRs that are health care providers may have specific compliance needs, such as auditing network adequacy, and MAOs may develop specific manuals and trainings for FDRs accordingly. MAOs may also have specific compliance obligations if the MAO is under common ownership with provider groups. The guidance also encourages participation in government information-sharing efforts aimed at combating fraud.
6. Be Cognizant of Vertically Integrated Organization Compliance Needs
As healthcare organizations increasingly combine insurance and provider operations, OIG expects compliance programs to evolve accordingly. The guidance recommends tailoring compliance structures to account for ownership arrangements, affiliated provider groups, and private equity or investor involvement. Training programs, including training for investors, should address the unique risks that can arise from these complex organizational structures.
7. Submit Accurate Claims
MAOs certify the accuracy of information submitted to CMS. Inaccurate submissions can create significant liability, including potential exposure under the False Claims Act. Strong controls around data validation, coding, and reporting are essential.
Building an Effective Medicare Advantage Compliance Program
Beyond the seven risk areas, OIG reiterates that MAOs are required to maintain compliance programs capable of preventing, detecting, and correcting noncompliance, as well as fraud, waste, and abuse. CMS routinely evaluates compliance program effectiveness through audits and oversight activities.
The guidance provides seven foundational elements of an effective compliance program:
- Written policies and procedures
- Strong compliance leadership and direct Board of Directors oversight over compliance
- Training and education
- Open communication and reporting mechanisms
- Consistent enforcement and accountability
- Risk assessment, auditing, and monitoring, including monitoring related to third parties
- Measuring compliance and taking prompt corrective action and remediation when issues are identified
Key Takeaways
The 2026 OIG Medicare Advantage guidance signals continued regulatory focus on beneficiary access, responsible marketing, risk adjustment integrity, third party oversight, and organizational accountability. An increasingly complicated MAO landscape, including third-party agents and vertically-integrated organizations, means that MAOs must be more vigilant than ever in their commitment to compliance. While the guidance itself not mandatory, it offers a clear view into OIG’s expectations and enforcement priorities. Medicare Advantage organizations that proactively align their compliance programs with these recommendations will likely be better positioned to manage regulatory risk and demonstrate a culture of compliance.
Recent Comments