Finding the error is not the same as proving the fix worked.

States should pay very close attention to GAO’s new review of Medicaid eligibility errors.

Not because it gives us another federal report to file away, and not simply because it identifies weaknesses in corrective action plans.

The bigger issue is what sits underneath those plans: years of eligibility error data showing where decisions are breaking, why they are breaking, what states chose to do about those failures, and whether anyone can demonstrate that the intervention changed the result.

In my view, that error evidence may be one of the most valuable management tools PERM produces.

GAO reviewed state-specific PERM reports from reporting years 2019 through 2025, along with MEQC results and corrective action plans from seven selected states. It found that caseworkers were generally the most prevalent root cause of eligibility errors. Across the PERM reports, missing key documentation was the most widespread specific cause: 47 states had at least one such error, accounting for 1,230 sample errors in GAO’s analysis. GAO also identified errors involving missed eligibility steps, incorrectly performed steps, and unmet timeliness standards.

Those are not merely audit findings. They are operational signals.

At the same time, GAO found that CMS had accepted PERM corrective action plans that were missing required elements and was not systematically analyzing eligibility errors and corrective actions across states and years. GAO recommended that CMS ensure CAPs include all required elements and systematically analyze the results over time. CMS agreed with the second recommendation and asked GAO to close the first; GAO maintained that additional action is still needed.

That matters now. Medicaid eligibility operations are entering another period of significant change, including more frequent redeterminations for certain enrollees and new community-engagement requirements. More decisions, more evidence, more interfaces, and more processing steps create more opportunities for error.

The management question is not whether states will have corrective actions.

They will.

The question is whether those corrective actions will actually work.

What are the error audits actually telling states?

The headline PERM rate matters, but the underlying error detail may be more useful to an operating executive.

GAO’s review shows that the error record can distinguish among failures caused by caseworker actions, eligibility systems, documentation gaps, missed processing steps, incorrect processing, and timeliness problems. That is far more actionable than a single statewide percentage.

A missing document problem is different from an income-calculation problem. A policy problem is different from a system defect. A system defect is different from a training failure. A recurring county or contractor issue is different from an isolated caseworker mistake.

Those differences should drive different responses.

If the same specific cause appears repeatedly across cases or cycles, the state should be asking whether it is looking at an individual error or an enterprise control failure.

That is why I would treat PERM and MEQC error reviews as a management dataset, not simply an audit output.

The error rate tells leaders that something happened. The error audit begins to tell them why.

Are states fixing the cause—or completing the corrective action?

GAO found that selected states used a familiar set of responses: training, guidance, eligibility-system changes, case reviews, staffing changes, and policy changes.

All of those can be appropriate.

But activity is not evidence of effectiveness.

Training can be delivered and the error can recur. Guidance can be issued and not change practice. A system change can be deployed and create a new exception path. A staffing intervention can improve timeliness while documentation quality deteriorates somewhere else.

A corrective action plan can therefore be complete as a project and incomplete as a control.

Federal PERM requirements recognize this distinction. States are required to evaluate prior corrective actions across five areas: improvements in operations, efficiencies, the number of errors, improper payments, and the state’s ability to meet PERM improper-payment-rate targets.

That is a demanding standard when taken seriously.

It asks more than: Did we implement the fix?

It asks: What changed after we implemented it?

How would we know whether the fix actually worked?

I would start by requiring a measurable hypothesis for every material corrective action.

If the root cause is incomplete verification evidence, what metric should improve? If the problem is untimely renewals, what processing measure should move? If incorrect system logic caused the error, what defect population should disappear after the release? If a contractor or county process is involved, what evidence will show that the delegated process changed?

The state should establish the baseline before the intervention whenever possible, identify the population affected, define the expected result, and then test again.

That does not require waiting three years for the next PERM cycle.

States already have quality-assurance activity, eligibility data, exception reporting, MEQC work, internal reviews, and the ability to conduct targeted or Shadow PERM testing. Those tools can be used to determine whether the error pattern is declining before the next federal sample arrives.

This is where the GAO report is especially important.

CMS officials told GAO they hope to use the Medicaid and CHIP Program Integrity Reporting Portal to compare eligibility error types, error rates, and corrective-action outcomes across states and cycles. But GAO reported that the system does not yet produce those analyses and that CMS had not begun systematically using the information that way.

States do not need to wait for a national analytic capability to begin asking the same question internally.

Did our intervention measurably change the error?

Could one corrective action create a different eligibility error?

This is the part of the control cycle that deserves more attention.

For eligibility, a successful corrective action cannot simply reduce improper approvals if it increases improper denials.

GAO emphasized that PERM corrective-action evaluations must also consider whether actions taken to reduce eligibility errors avoid increases in improper denials. MEQC is especially important here because it examines both approvals and denials.

That is not a technical footnote. It is a management safeguard.

Imagine a state responds to weak verification by adding more manual documentation requirements. Approval errors may decline. But processing time may increase, unresolved cases may accumulate, and eligible people may be denied because the new process is difficult to complete.

A state could improve one measure and worsen another.

That is why corrective-action effectiveness should be tested across the entire eligibility decision—not only against the error that originally drew attention.

The question is not merely: Did the original error decrease?

It is also: What happened around it?

What should Medicaid executives require before they call the issue closed?

I would require five things.

First, a clearly stated root and specific cause. “Human error” is not enough. Leaders need to know what action was taken or missed, under what rule, in what workflow, and under what conditions.

Second, a corrective action tied directly to that cause. Training should not be the default response to a system defect, and a system change should not substitute for a policy or accountability problem.

Third, a measurable effectiveness standard established before closure. The state should know what outcome would constitute improvement.

Fourth, follow-up testing. The affected population should be reviewed again after implementation, using internal quality work, MEQC, targeted sampling, Shadow PERM, or another defensible method.

Fifth, executive evidence of closure. Someone should be able to show what failed, what changed, what the post-intervention data showed, whether any new denial or access risk appeared, and who accepted any remaining risk.

I would also expect that evidence to survive organizational boundaries.

If the error involves a county, eligibility broker, data broker, system integrator, or other contractor, the state still needs the records necessary to demonstrate that the corrective action changed the result. Delegating part of the process cannot mean delegating away the evidence of effectiveness.

My conclusion

My conclusion is that states should stop treating PERM eligibility error audits primarily as retrospective compliance exercises.

They are management data.

The real value is not simply knowing that an error occurred. It is knowing why it occurred, whether the same cause is recurring, what intervention was chosen, and whether subsequent evidence proves that the intervention changed the result.

A corrective action should not be considered complete because training occurred, guidance was distributed, a system change was released, or a CAP was accepted.

It should be complete when the state can demonstrate that the targeted error pattern declined without creating a different eligibility problem elsewhere.

That requires states to follow errors across time, compare corrective actions with outcomes, preserve the evidence that connects the intervention to the result, and make effectiveness—not activity—the standard for closure.

With major eligibility changes ahead, I would not wait for the next PERM sample to discover whether today’s controls worked.

Finding the error tells you where the control failed. Proving the fix worked tells you whether you actually changed it.

PERM Finding Response Path

Shadow PERM Implementation Guide

PERM Eligibility Risk: From Audit Event to Operational Discipline

Primary sources

Keep Reading