Two major developments are approaching Medicaid eligibility operations at nearly the same time.
Beginning January 1, 2027, states generally must implement new Medicaid community-engagement requirements for certain adults, including an 80-hours-per-month requirement that may be satisfied through work, education, work programs, community service, or qualifying income. States will also have to determine who is subject to the requirement, identify exceptions, verify compliance, provide notices, and report information to CMS.
At the same time, CMS has made an unusual change to the Payment Error Rate Measurement program: RY2027 will exclusively measure eligibility, with no medical-record outreach for that cycle.
It is tempting to connect those facts and conclude that the 2027 PERM cycle will test the implementation of Medicaid work requirements.
That would be too simple—and technically inaccurate.
The RY2027 PERM measurement period involves payments from an earlier period, before the January 2027 implementation deadline.
But Medicaid leaders should not dismiss the convergence.
RY2027 may not measure the new community-engagement rules. It may reveal whether states possess the eligibility-control environment they will need when those rules eventually enter the PERM measurement window.
An eligibility-only cycle deserves unusual attention
PERM normally examines multiple components of Medicaid and CHIP improper payments. CMS's temporary decision to make RY2027 eligibility-only changes the emphasis.
For the states in that rotation, there will be no medical-record outreach. The measurement focus will be eligibility.
That matters because eligibility remains a material source of improper-payment risk. CMS reported a 4.42% national rolling Medicaid eligibility improper-payment rate for 2025, up from 3.31% in 2024.
An eligibility-only PERM cycle therefore offers something more useful than another compliance deadline.
It provides a concentrated test of the infrastructure beneath eligibility determinations:
policy interpretation, verification, case documentation, systems logic, interfaces, notices, worker procedures, quality assurance, exception handling, and governance.
Those are precisely the capabilities that will become more important—not less—as community-engagement requirements are implemented.
The difficult part may not be counting 80 hours
The headline requirement is easy to understand: certain adults must satisfy 80 hours per month through qualifying activities or otherwise meet the applicable standard.
The operational challenge is considerably more complicated.
CMS places responsibility on states for determining who is subject to the requirement and who qualifies for an exception; verifying compliance at application and renewal; providing outreach and notice; taking specified action when compliance cannot be verified; and submitting data needed for monitoring and program integrity.
That creates multiple decision points around a single individual.
Is this person in the applicable eligibility group?
Is an exception present?
Has the exception been adequately established?
Can qualifying activity be verified electronically?
What happens when electronic information is incomplete?
Was notice provided correctly?
Was the individual given the required opportunity to respond?
Was the resulting eligibility action properly documented?
Each question can create a distinct pathway to an erroneous determination.
The greatest risk may therefore not be whether a state can calculate 80 hours.
It may be whether a state can consistently determine when the 80-hour test should be applied at all.
Exceptions are controls, not footnotes
Community-engagement policy inevitably draws attention to the people required to comply. From an operational-risk perspective, equal attention should be paid to people who should not be subjected to the requirement.
CMS identifies numerous populations and circumstances that can remove an individual from the requirement or change how it applies.
Every exception introduces another eligibility determination.
And every determination requires evidence.
This is where policy simplification, self-attestation, automated data sources, manual verification, and documentation standards become consequential.
A state can adopt a policy designed to minimize beneficiary burden and still need to answer a very different question later:
What evidence demonstrates that the resulting eligibility decision complied with federal requirements?
That is the PERM question.
The answer cannot be invented after the sample is drawn.
Documentation will become part of the fiscal control environment
Community-engagement implementation is likely to produce large volumes of eligibility transactions across systems that were not originally designed around this particular requirement.
States may rely on wage information, SNAP or other program data, educational information, caseworker input, beneficiary attestations, interfaces, and exception determinations.
The operational temptation will be to focus on whether the transaction can be completed.
The stronger question is whether it can later be reconstructed.
Could an independent reviewer determine what information was available, which rule applied, whether an exception was evaluated, what verification occurred, what notice was issued, and why Medicaid eligibility continued or ended?
If not, the state may possess an administrative outcome without possessing a defensible audit record.
That distinction will become increasingly important as these requirements mature into future PERM measurement periods.
RY2027 should be treated as a readiness assessment
States participating in the RY2027 cycle have an unusual opportunity.
Rather than treating an eligibility-only PERM cycle simply as something to survive, they can use it as a diagnostic exercise for the eligibility environment that will soon absorb substantially more complexity.
Other states should pay attention to the findings as well.
The questions are transferable:
Can eligibility decisions be reconstructed from the system record?
Are verification sources and timestamps retained?
Are exceptions documented as carefully as requirements?
Do manual processes create gaps that automated processes do not?
Can policy changes be traced into worker instructions and systems logic?
Are quality reviews identifying documentation weaknesses before federal review does?
Is responsibility clear when multiple agencies, counties, vendors, or data sources contribute to a determination?
Those questions are not specific to one PERM cycle.
They define whether an eligibility operation is prepared for the next generation of federal requirements.
The real PERM exposure comes later
The implementation timeline also creates an important governance point.
Because the RY2027 measurement period predates the January 2027 community-engagement implementation deadline, states should not interpret a favorable RY2027 result as evidence that their new work-requirement processes are PERM-safe.
They will not yet have been tested in that measurement.
The meaningful exposure comes in later PERM cycles as post-implementation eligibility determinations enter the sampled payment periods.
That creates a window for action.
States do not have to wait for those findings.
They can use current PERM results, MEQC work, quality-control reviews, implementation testing, and pre-production simulations to identify weaknesses before the new policy appears in a federal sample.
That is far less expensive than discovering them afterward.
A better executive question
The question for Medicaid leadership should not be:
Will the 2027 PERM cycle measure work requirements?
It largely will not.
The better question is:
What will the 2027 eligibility-only cycle tell us about whether our eligibility operation is capable of implementing the next wave of requirements without creating preventable audit and fiscal exposure?
That is the more useful connection between these two federal developments.
PERM is retrospective by design.
Executive risk management does not have to be.
RY2027 may not be the federal test of community-engagement implementation. But for states willing to learn from it, it can be the rehearsal before the test begins.
