Loading...
GAO found significant gaps in VA’s Community Care program and CMS’s Medicare Advantage program that leave both designated high-priority for improper payments in FY2025. VA reported a Community Care improper payment estimate of $608 million (2.4% of outlays) and has processes to identify root…
Breaking analysis of what happened and who is affected.
GAO found significant gaps in VA’s Community Care program and CMS’s Medicare Advantage program that leave both designated high-priority for improper payments in FY2025. VA reported a Community Care improper payment estimate of $608 million (2.4% of outlays) and has processes to identify root…
Read full report →Segment ImpactDeep dive into how this impacts each market segment.
The GAO report identifies the VA Community Care program and CMS’s Medicare Advantage program as high-priority improper payment risks for fiscal year 2025. VA reported a Community Care improper payment estimate of $608 million (2.4 percent of outlays) for FY2025; CMS reported a Medicare Advantage…
Read full report →Action KitActionable checklists and implementation guidance.
The GAO has designated VA’s Community Care program and HHS’s Medicare Advantage program as high-priority for improper payments for fiscal year 2025. VA reported an estimated $608 million (2.4% of outlays) in Community Care improper payments for FY2025, and CMS reported an estimated $23.7 billion…
Read full report →GAO found significant gaps in VA’s Community Care program and CMS’s Medicare Advantage program that leave both designated high-priority for improper payments in FY2025. VA reported a Community Care improper payment estimate of $608 million (2.4% of outlays) and has processes to identify root causes and implement corrective actions, but lacks a comprehensive fraud risk assessment. CMS reported a Medicare Advantage improper payment estimate of $23.7 billion (6.1% of outlays) and, while it identifies root causes, its corrective action plans—especially for expediting Risk Adjustment Data Validation (RADV) audits—are not sufficiently detailed and a RADV audit backlog delays recoveries; CMS also lacks a comprehensive fraud risk assessment. This raises near-term program integrity, recovery, and compliance risk for contractors operating in Healthcare Services, Revenue Cycle, Risk Adjustment, Medical Auditing, and Fraud Detection segments. Immediate implications: heightened audit pressure, potential for increased oversight and recovery actions, and greater scrutiny of billing, documentation, and fraud controls. Contractors should assume follow-on agency activity and prepare to support RADV and related audit workflows while monitoring solicitations and corrective-action opportunities.
Affected market segments at a glance:
Specific NAICS codes, agencies, contract vehicles, and compliance regimes explicitly identified in the segmentation:
A: GAO found both programs are on OMB’s high-priority improper payments list for FY2025. VA estimated $608 million (2.4% of outlays) for Community Care and has implemented root-cause processes and corrective actions but lacks a comprehensive fraud risk assessment. CMS estimated $23.7 billion (6.1% of outlays) for Medicare Advantage, has root-cause identification but weak corrective-action detail and monitoring—particularly a backlog and insufficient plan for RADV audits—and has not completed a comprehensive fraud risk assessment.
A: Expect increased agency scrutiny around documentation, coding, risk-adjustment submissions, and audit support requests (including RADV-related activities). Specific enforcement actions, timelines, or new solicitations—Pending source review.
A: Prioritize secure, audit-ready claims documentation; validate risk-adjustment data and submission controls; review internal fraud risk processes; and activate monitoring and capture workflows to identify corrective-action contract opportunities. For detailed playbook and automation, see the Intelligence Response below.
See the primary hub for capture fundamentals: Winning Federal Contracts Guide (/insights/winning-federal-contracts). For compliance and CUI (Controlled Unclassified Information) handling references, see CMMC (Cybersecurity Maturity Model Certification) Compliance Guide (/insights/cmmc-compliance-guide) and CUI-Safe CRM Guide (/insights/cui-safe-crm-guide).