PERM is often discussed as though Medicaid and the Children’s Health Insurance Program sit inside a single payment-error framework.
From a measurement perspective, they largely do.
CMS measures improper payments in both Medicaid and CHIP. Both programs are reviewed for fee-for-service, managed care, and eligibility errors. Both produce national and state improper-payment results. And both can be affected by many of the same eligibility-system weaknesses: missing verification, insufficient documentation, incorrect program assignment, faulty system logic, and incomplete case records.
But measurement is not the same thing as fiscal consequence.
That distinction becomes more important under H.R. 1.
Beginning in fiscal year 2030, Congress changes the rules governing Medicaid eligibility-related erroneous excess payments under section 1903(u) of the Social Security Act. The law does not eliminate the longstanding good-faith waiver authority.
It limits it.
And that means Medicaid executives increasingly need to distinguish among three questions that are too often collapsed into one:
What did PERM measure?
Which program generated the error?
Which statutory recovery rule applies to the dollars?
One measurement program does not mean one fiscal regime
CMS reports Medicaid and CHIP improper-payment rates separately.
For FY2025, the national rolling Medicaid eligibility improper-payment rate was 4.42%, while the corresponding CHIP eligibility rate was 5.23%.
Those numbers illustrate an important point—but not the one leaders sometimes assume.
They are national rolling estimates. They are not themselves state disallowance calculations.
For Medicaid, the statutory fiscal-control mechanism appears in section 1903(u). When a state’s erroneous excess payments exceed the statutory 3% allowable error rate, federal financial participation may be reduced with respect to the excess. Current PERM regulations implement that framework for eligibility improper-payment findings.
CHIP follows a different recovery pathway.
Federal regulations explicitly distinguish the two programs: erroneous Medicaid eligibility payments are addressed under section 1903(u), while CHIP federal-payment reductions operate under the separate Title XXI authority in section 2105(e).
That distinction matters.
PERM can identify similar eligibility-control failures in both programs without producing identical federal fiscal consequences.
H.R. 1 did not eliminate the Good Faith Effort Waiver
This point deserves particular clarity because earlier versions of federal legislation created understandable confusion.
The enacted law—Public Law 119-21—does not repeal section 1903(u)(1)(B), the Medicaid good-faith waiver authority.
Instead, beginning with fiscal year 2030, section 71106 adds a statutory limitation to the amount that may be waived.
Under current PERM regulations, when CMS concludes that a state exceeded the 3% threshold despite a good-faith effort, the state may receive relief from the eligibility disallowance, provided it satisfies specified PERM corrective-action and MEQC requirements.
H.R. 1 changes that future landscape.
The amended statute provides that the amount waived for a fiscal year may not exceed the erroneous excess payments described in section 1903(u)(1)(D)(i)(II), above the allowable 3% error rate.
The practical interpretation is therefore not:
The waiver disappears.
It is:
The waiver survives, but Congress places a ceiling on how much relief the Secretary may provide.
That is a materially different proposition.
The worst-case risk was already serious
It is tempting to describe this change as creating an entirely new Medicaid clawback risk.
That overstates the statute.
Section 1903(u) already establishes the 3% threshold and authorizes federal payment reductions for erroneous excess payments above that level. The possibility of a substantial eligibility-related disallowance therefore predates H.R. 1.
What changes is the mitigation environment.
Historically, the good-faith framework could significantly reduce the consequence for a state that could demonstrate that it had taken the required corrective actions and nevertheless failed to meet the threshold.
Beginning in FY2030, even a state that establishes a qualifying good-faith case will face a statutory limit on how much CMS may waive.
That means the better executive framing is:
H.R. 1 does not necessarily make the theoretical maximum loss newly severe. It makes the pathway to mitigating that loss more constrained.
For risk management, that distinction matters.
Expected exposure depends not only on the maximum possible disallowance, but also on the mechanisms available to reduce it.
Error classification now matters more
The statutory amendment creates another challenge that deserves attention well before FY2030.
Future waiver capacity is tied to a specific category of erroneous excess payments described in amended section 1903(u)(1)(D).
CMS already publishes detailed PERM eligibility error information. The 2025 supplemental data, for example, distinguishes among errors involving missing verification, incomplete documentation, inability to determine eligibility, financial and nonfinancial ineligibility, incorrect program assignment, and incorrect FMAP assignment.
But those operational PERM error codes are not the same thing as a historical fiscal crosswalk to the newly amended statutory categories.
That is important.
The enacted amendment changes section 1903(u)(1)(D), including new treatment of payments where insufficient information is available to confirm eligibility and an additional statutory category concerning payments for services furnished to individuals who were not eligible for the particular medical assistance.
CMS has not yet provided a historical data series that lets states simply take previous PERM results and reliably calculate what the future H.R. 1 waiver ceiling would have been.
So historical PERM rates should not be converted mechanically into predicted FY2030 disallowances.
The data do not yet support that degree of precision.
That uncertainty is itself an executive issue.
States should begin asking whether their internal analytics can distinguish not merely how many eligibility errors occurred, but:
what type of error occurred;
what federal dollars were associated with it;
whether eligibility could not be confirmed because evidence was insufficient;
whether the individual was actually ineligible;
whether the wrong program or eligibility category was assigned;
and how the error would map to the future statutory recovery framework.
The future fiscal question may depend increasingly on the composition of the error rate, not simply the rate itself.
CHIP should not be treated as Medicaid with a different match rate
This is where the Medicaid/CHIP distinction becomes especially valuable.
PERM regulations deliberately cover both programs. CMS defines and measures eligibility errors for Medicaid and CHIP, and the same state eligibility infrastructure may support both populations.
But section 71106 amends Medicaid section 1903(u).
It does not convert CHIP recoveries into the Medicaid 3% disallowance-and-waiver structure.
Federal regulations continue to direct CHIP recoveries through section 2105(e) and the Title XXI framework.
That creates a potentially important operational asymmetry.
A single system defect might affect:
a Medicaid case;
a CHIP case;
and perhaps even the transition between the two programs.
CMS’s own 2025 data include errors in which an individual should have been enrolled in a different program—Medicaid or CHIP.
The upstream control problem may therefore be identical.
The downstream fiscal treatment may not be.
Most state eligibility operations do not maintain completely independent control environments for Medicaid and CHIP.
The programs commonly rely on overlapping:
eligibility workers;
verification sources;
rules engines;
noticing processes;
interfaces;
case-management systems;
vendors;
and evidence-retention practices.
That creates an important leadership lesson.
The fact that Medicaid and CHIP ultimately follow different federal fiscal authorities does not mean states should manage the underlying controls separately.
If income verification fails, both programs may be affected.
If an interface does not preserve authoritative source results, both programs may be affected.
If documentation cannot reconstruct why a case was placed in Medicaid rather than CHIP, both programs may be affected.
If system logic applies the wrong eligibility category or federal match rate, the consequence may extend beyond basic eligibility accuracy.
CMS has repeatedly emphasized that insufficient documentation and missing eligibility verification remain major sources of Medicaid and CHIP improper payments.
The operational control should therefore be common even when the fiscal consequence is not.
The 3% question is no longer enough
Medicaid executives have historically had an obvious PERM question:
Are we above or below 3%?
That remains important.
But it is increasingly insufficient.
A more mature executive dashboard should eventually answer:
Which program generated the improper payment?
Which eligibility error category generated it?
How many federal dollars are associated with each category?
How much resulted from inability to demonstrate eligibility rather than confirmed substantive ineligibility?
Did the error involve incorrect Medicaid-versus-CHIP placement?
Which control failed upstream?
And which statutory recovery authority governs the consequence?
That changes PERM from a scorecard into a fiscal-risk model.
It also reinforces an important distinction throughout eligibility oversight:
Accuracy and defensibility are related, but they are not identical.
A state may believe the underlying eligibility decision was reasonable.
PERM still requires sufficient evidence to demonstrate that the decision complied with applicable requirements.
CMS’s current improper-payment guidance explicitly recognizes circumstances where the available record is insufficient to determine whether a payment was proper.
H.R. 1 makes that distinction more consequential by explicitly incorporating insufficient-information circumstances into the future statutory definition of erroneous excess payments.
Do not attach the change prematurely to RY2029
There is also a timing issue worth resisting.
Section 71106 is expressly effective beginning with fiscal year 2030, which begins October 1, 2029.
That does not automatically mean states should describe the change publicly as an “RY2029 PERM rule.”
PERM review years operate on their own measurement timelines, while the statute uses a federal fiscal-year effective date. CMS will need to explain how the amended section 1903(u) calculation interacts with PERM review years, payment periods, and future disallowance determinations.
Until that implementation guidance is available, the more defensible description is:
The statutory restriction begins in FY2030.
That avoids creating precision the federal government has not yet supplied.
The executive issue is fiscal traceability
The larger lesson is not that Medicaid has suddenly become financially risky while CHIP has not.
Both programs already require disciplined eligibility operations.
Both experience improper payments.
Both can generate federal recoveries.
And both depend on states' ability to demonstrate why federal dollars were properly claimed.
What changes under H.R. 1 is the importance of tracing Medicaid eligibility errors all the way from the individual case to the statutory fiscal consequence.
State leaders should increasingly be able to follow this chain:
eligibility evidence → decision → program assignment → error classification → federal dollars → recovery authority
If that chain cannot be reconstructed, knowing the aggregate PERM rate will provide only part of the risk picture.
PERM measures Medicaid and CHIP.
But it does not make them fiscally interchangeable.
And beginning in FY2030, asking whether a state's Medicaid eligibility error rate exceeds 3% will no longer be enough.
Leaders will need to know which program generated the error, what kind of error produced the dollars, what evidence supports the determination, and which federal recovery rule governs the consequence.
Sources
CMS, PERM Error Rate Findings and Reports, including 2025 Medicaid and CHIP eligibility improper-payment rates.
CMS, 2025 Medicaid & CHIP Supplemental Improper Payment Data, including Medicaid eligibility error categories and projected federal improper payments.
Social Security Act §1903(u), 42 U.S.C. §1396b(u), including the amendment enacted by Public Law 119-21 §71106 effective beginning FY2030.
42 CFR §431.1010, Medicaid eligibility improper-payment disallowances and good-faith provisions.
42 CFR §431.1002, separate Medicaid and CHIP recovery authorities.
CMS, FY2025 Improper Payments Fact Sheet.
