Self-attestation occupies an unusual place in Medicaid administration.
To advocates of administrative simplification, it can reduce unnecessary paperwork, accelerate enrollment, and prevent eligible people from losing coverage because they cannot readily produce a document. To program-integrity professionals, the same practice can raise concerns about verification, consistency, and whether an eligibility decision will withstand scrutiny months or years later.
Both perspectives can be legitimate.
The more useful question is not whether Medicaid should permit self-attestation. Federal Medicaid rules already contemplate it. The more consequential question is whether a state that relies on an attestation has built sufficient controls around the decision.
That distinction is becoming increasingly important as states prepare for the new Medicaid community-engagement requirements taking effect in 2027.
Self-attestation is already part of Medicaid
Federal regulations do not treat attestation as inherently suspect. Except where law requires another verification method, Medicaid agencies may accept an individual's attestation of information needed to determine eligibility. At the same time, agencies remain responsible for requesting and using information relevant to verification and maintaining a state verification plan.
The verification framework also embodies an important principle of modern Medicaid administration: do not demand documents unnecessarily. When information provided by an applicant or beneficiary is reasonably compatible with electronic data available to the agency, eligibility generally should be determined using that information. When the information conflicts, the agency may need additional explanation or documentation. Federal rules also preserve self-attestation in specified circumstances when documentation does not exist or is not reasonably available.
That structure recognizes a real operational tension.
A program can create error by asking for too little evidence. It can also create error—and unnecessary loss of coverage—by asking people to prove facts the government can already establish through its own data.
Good eligibility administration therefore is not synonymous with collecting the greatest possible quantity of paper.
It is about obtaining the right evidence, at the right point in the decision, and preserving enough information to explain why the decision was reasonable.
2027 changes the stakes
Beginning January 1, 2027, states generally must implement the new federal community-engagement requirement for certain Medicaid adults. CMS's June 2026 rule requires affected individuals to demonstrate qualifying activity, generally equivalent to 80 hours per month, unless they qualify for an exclusion or other applicable exception. States are responsible for determining who is subject to the requirement, verifying compliance, identifying exclusions, issuing notices, and submitting information that supports federal monitoring and program integrity.
That creates an entirely new set of operational decisions.
Is the individual subject to the requirement?
Does an exclusion apply?
Was the exclusion established from data already available to the state, information supplied by the individual, documentation, or some combination?
For what period does the determination remain valid?
What happens when new information conflicts with the original determination?
And, perhaps most importantly from an audit perspective, could another reviewer later reconstruct exactly what happened?
Medical frailty illustrates the challenge particularly well.
Under the new rule, states first must attempt to verify medical frailty or special medical needs using reliable information available to them, including relevant adjudicated claims and encounter data. Through December 31, 2027, when reliable information is unavailable or is not reasonably compatible with information supplied on behalf of the individual, a state may require documentation or accept a statement or other sufficient information under penalty of perjury. Beginning in 2028, the rule places tighter limits on repeated reliance on that approach and requires subsequent verification through reliable state information or documentation in specified circumstances.
That 2027 flexibility should not be confused with the absence of a control requirement.
It is better understood as a transition period in which states have discretion over how an eligibility fact is verified—not whether the resulting decision needs to be governed, retained, and defensible.
Where the risk actually begins
Self-attestation becomes operationally risky when the organization cannot answer a series of basic questions:
• Authority: What statute, regulation, state policy, waiver provision, or approved verification plan permits the attestation?
• Evidence: What information did the individual provide, what electronic data were available, and were they reasonably compatible?
• Decision: What eligibility rule was applied and why did the information satisfy it?
• Exception governance: Who may approve unusual cases, how are exceptions coded, and how are they reviewed for consistency?
• Retrospective testing: Does the state periodically sample these determinations to determine whether the policy is producing accurate, supportable, and consistently documented outcomes?
None of those controls requires converting every Medicaid application into a paper-intensive process.
They require something different: decision discipline.
A well-controlled self-attestation process can be easier for members than a documentation-heavy process while simultaneously being more defensible than an environment in which workers collect documents inconsistently, systems overwrite evidence, or policy exceptions are handled differently from office to office.
PERM makes the distinction important
CMS has repeatedly emphasized that an improper payment is not necessarily evidence of fraud or even proof that the beneficiary was substantively ineligible.
Documentation matters.
CMS's most recent improper-payment materials explain that improper payments frequently arise because a reviewer cannot determine whether a payment was proper due to insufficient documentation. In Medicaid and CHIP, that can include the absence of a record showing that an eligibility factor was appropriately verified. Conversely, CMS describes proper payments as including situations in which the state appropriately maintains documentation of the eligibility verification requirement and determines eligibility according to applicable rules.
That is the critical distinction between eligibility accuracy and audit defensibility.
A person may in fact have been eligible.
The worker may have made what appears to be the right decision.
But if the state cannot later establish what information was used, what rule applied, and why the determination was permissible, the audit outcome may look very different from the operational intent.
That issue deserves particular attention because CMS has temporarily made Reporting Year 2027 an eligibility-only PERM cycle. Medical and data-processing reviews are being suspended for that cycle while eligibility continues to be measured.
The timing does not mean the new community-engagement requirement will automatically become the subject of every 2027 PERM review. It does, however, reinforce a broader lesson: eligibility controls are moving closer to the center of federal Medicaid oversight.
Access and program integrity are not opposites
The debate around verification is often framed as a choice.
One side emphasizes access: reduce paperwork, use electronic sources, trust applicants where permitted, and avoid procedural terminations of people who remain eligible.
The other emphasizes integrity: verify eligibility, protect public funds, maintain documentation, and prevent inappropriate enrollment.
Medicaid leaders should resist that binary.
A strong eligibility system should be capable of doing both.
Electronic verification can reduce burden and improve accuracy. Reasonable-compatibility rules can prevent needless documentation requests and establish a disciplined response when information conflicts. A carefully designed attestation can preserve coverage for someone who cannot immediately obtain supporting documentation and create a structured record that can later be tested against claims, encounter data, or other reliable information.
The control does not have to be imposed entirely at the front door.
It can be distributed across the eligibility lifecycle.
That is particularly important for populations such as people with unstable employment, homelessness, rapidly changing health conditions, or limited ability to obtain traditional records. An eligibility process designed solely around the easiest cases to document will predictably create barriers for some of the people Medicaid was designed to serve.
But administrative compassion should not be mistaken for administrative ambiguity.
The more flexibility an organization introduces at the point of determination, the more deliberate it should be about downstream reconciliation, sampling, exception management, and evidence retention.
This is an executive decision, not merely a procedural one
That leads to a governance issue that deserves more attention.
Expanding the use of self-attestation may appear to be an eligibility-operations decision. In reality, a material change can alter member experience, workforce requirements, system logic, quality-control workload, appeal exposure, PERM risk, and ultimately state fiscal exposure.
Those consequences extend beyond the eligibility unit.
For significant policy changes, leaders should know what level of risk is being accepted, what mitigating controls have been designed, who owns those controls, and what evidence will tell the organization whether the policy is working as intended.
That does not mean every verification decision belongs before a governor, legislature, Medicaid board, or cabinet official.
It does mean that major expansions of discretion should not disappear inside a procedure manual without visible executive ownership of the resulting risk.
A useful governance question is simple:
If this policy eventually contributes to a material federal audit finding, would the people accountable for the program be able to demonstrate that the risk was understood, consciously accepted, and appropriately controlled?
If the answer is unclear, the governance process is probably incomplete.
The real test
The future of Medicaid eligibility administration will almost certainly involve more—not less—use of automated data, cross-program information, simplified member interactions, and decision rules that reduce unnecessary paperwork.
Self-attestation can fit comfortably within that future.
But simplicity for the applicant cannot mean opacity for the organization.
A defensible program should be able to reconstruct the eligibility decision after the employee who made it has moved on, after systems have changed, and after the case has become one item in a federal sample.
That is the standard worth designing toward.
The risk is not that a Medicaid member made a statement.
The risk begins when the state can no longer demonstrate what it knew, why it relied on that information, how it reached the decision, and whether its controls worked.
Selected Sources
42 CFR § 435.945 — General requirements for Medicaid verification
42 CFR § 435.952 — Use of information and requests for additional information
CMS — Medicaid Community Engagement Requirement for Certain Individuals, Interim Final Rule Fact Sheet
42 CFR § 435.557 — Medical frailty and special medical needs
CMS — Fiscal Year 2025 Improper Payments Fact Sheet
CMS — Payment Error Rate Measurement (PERM)
