CMS 2025 Audit and Enforcement Report: What Compliance Teams Need to Know
July 30, 2026
CMS has published its CY 2025 Part C and Part D Program Audit and Enforcement Report. The 20-page report covers three audit-process pilots, six lessons drawn from program audits and enforcement evaluations, 14 Civil Money Penalties, the intermediate sanctions in effect during 2025, and the agency's stated priorities going forward.
This article summarizes the full report so you can work from it without reading the PDF, and separates three things that are easy to blur together: what CMS actually reported, how we read it, and what a compliance team might do about it. Where our interpretation goes beyond the document, we say so.
Key Takeaways
- •CMS piloted a more integrated approach to Compliance Program Effectiveness in one 2025 audit, folding compliance discussions into the operational program areas under review.
- •Advance desk reviews let auditors examine case documentation before live webinars, shifting fieldwork time from document hunting to substantive discussion.
- •75 percent of findings were validated without a full validation audit, and average closure time fell from 219 days to 150.
- •The six lessons point at system testing, data reconciliation, delegated oversight, clinical review, care coordination, and routine monitoring.
- •14 CMPs totaling roughly $1.54 million covered 18 violations tied to oversight conducted in 2025. Financial harm above $100 was present in 89 percent of them.
- •Looking forward, CMS expects compliance officers to demonstrate that prior-authorization timeframes, delegated workflows, and submitted data are actively monitored and validated.
In this article
- 1. Why 2025 was not a typical audit year
- 2. Three changes CMS piloted
- 3. What CMS learned from program audits
- 4. What CMS learned from enforcement evaluations
- 5. What the CMP numbers show
- 6. Intermediate sanctions in effect during 2025
- 7. What CMS evaluates during program audits
- 8. What CMS says to prepare for next
- 9. CMS's audit-preparation recommendations
- 10. Six control questions to ask now
- 11. Where technology fits
- 12. The bottom line
Why 2025 was not a typical audit year
A bid protest reduced the number of program audits CMS could conduct in 2025. CMS used the reduced volume to pilot changes aimed at lowering administrative burden, making fieldwork more substantive, and concentrating validation resources on the conditions that carry the most compliance risk.
One framing note before the substance. The report does not disclose how many audits were conducted, how many findings were issued, or how many sponsors sit behind each lesson, so it should not be read as a prevalence study. What it does provide is a map of the operational failures CMS encountered and the controls worth testing against them.
Three changes CMS piloted in its audit process
1. Integrating CPE into operational audit discussions
CMS used one of its 2025 program audits to pilot a revised approach to Compliance Program Effectiveness (CPE). Instead of treating CPE purely as a separate tracer review, CMS integrated compliance discussions into the operational program areas being audited, with the compliance officer participating as concerns emerged during fieldwork.
The pilot still included all of the following:
- • A Compliance Oversight Activities (COA) universe and questionnaire before fieldwork
- • A pre-audit interview with the compliance officer
- • Compliance officer participation during operational fieldwork
- • A post-fieldwork compliance officer interview
That last point is worth stating plainly, because the pilot is sometimes described as having replaced the compliance officer interviews. It did not. Both the pre-audit and the post-fieldwork interviews remain in the process CMS describes.
CMS reviewed the COA universe alongside audit findings to evaluate whether the sponsor had already identified the relevant risks, whether existing monitoring was effective, and how the organization responded once problems surfaced.
The practical implication: a COA universe cannot simply document that monitoring activities exist. It needs to be consistent with what CMS sees in the operational discussions for ODAG, CDAG, FA, and SNPCC. Our CPE and COA quick reference covers the universe structure and what the discussion-based review asks for.
2. Moving case review ahead of live webinars
CMS also piloted desk reviews of case documentation. Auditors reviewed the material before the live webinar so they could identify questions and potential concerns in advance, and sponsors gained time to locate records, coordinate with delegated entities, and line up the right subject matter experts.
CMS reported that the approach:
- • Reduced time spent locating documents during webinars
- • Produced more focused discussions
- • Improved transparency by providing questions in advance
- • Freed webinar time for operational processes, risks, and corrective actions
CMS's own tips for sponsors: review every requested case file carefully, flag unavailable documents before the webinar rather than letting them surface as a question, package large PDFs in a ZIP file for HPMS upload, and read the follow-up questions before deciding who needs to be on the call.
3. Streamlining validation of audit findings
Historically, conditions requiring correction were generally validated through a full validation audit, which could mean new universes and additional sample testing. In 2025 CMS piloted a more targeted approach, setting the validation method based on the nature, scope, complexity, and root cause of the condition. A corrected notice template or system configuration, for example, could be confirmed through a webinar or targeted document review instead of a complete validation audit.
This does not lower the bar for corrective-action evidence. It means sponsors should be ready to demonstrate a correction through whichever form of evidence actually fits the underlying failure.
What CMS learned from program audits
Lesson 1: Small data errors can become beneficiary access problems
CMS found that enrollment-processing errors, system configuration problems, and insufficiently tested changes could stop beneficiaries from receiving covered medications, services, or benefits. The examples cited:
- • Coverage deactivated when members moved between plan benefit packages
- • Weekend eligibility file processing temporarily terminating active coverage
- • Manual enrollment updates producing incorrect eligibility information
- • Transition-eligible enrollees denied medication because a system relied on prior enrollment dates instead of current effective dates
- • Duplicate logic in a prior-authorization system failing after an update, causing appeals to process incorrectly
- • System edits making approved coverage requests unavailable for the full plan year
- • Technical failures preventing automatic care plan generation
- • Vendor mailing processes falling out of alignment with CMS timeliness requirements after system changes
CMS recommends validating enrollment and eligibility updates before implementation, testing system changes both before and after deployment, reconciling data following updates and transitions, and monitoring rejected claims and denied requests for unusual patterns.
Our read: the control question is whether the sponsor can identify a data or configuration problem before it becomes a beneficiary access problem. Each example points to an internal control that could have been tested before beneficiary impact occurred.
Lesson 2: Delegation does not transfer accountability
Sponsors may contract with first-tier, downstream, and related entities (FDRs) to administer Part C and Part D benefits. CMS's position is unchanged: the sponsor remains accountable for work performed on its behalf. CMS identified:
- • Utilization management edits applied inconsistently with approved benefit designs
- • Delegated decisions inconsistent with Medicare coverage requirements or the sponsor's approved plan benefit package
- • Claims processing vendors contributing to untimely notices or payments
- • The new 65-day appeal timeframe implemented inconsistently across systems and delegated entities
- • Dismissal notices omitting required language on vacating dismissals and requesting reconsideration
- • Quality-of-care grievance resolution letters incorrectly including Medicare appeal rights
- • Extension notices that failed to explain why a decision timeframe was being extended
CMS advises validating vendor system edits, monitoring delegated-entity performance, and testing denial notices and other messaging across platforms.
Our read: the 65-day appeal timeframe is the useful test case. Trace one regulatory change end to end and see whether you can produce the trail: sponsor policy updated, delegated entities notified, systems configured, notice templates revised, quality review performed, monitoring in place. A common weak point is proving implementation beyond the initial policy update and delegate communication. Guidance distribution and policy management exist to make that trail reconstructable after the fact.
Lesson 3: Coverage decisions require complete information
Auditors identified coverage decisions made without all relevant clinical or enrollee-specific information:
- • Appeals submitted by different prescribers processed as second coverage determinations rather than redeterminations
- • Duplicate logic failures causing redeterminations to process incorrectly
- • Decisions made without considering all available enrollee information
CMS recommends reviewing denial trends, auditing medical-necessity decisions, and ensuring reviewers receive the complete clinical documentation relevant to the request. The report is specific on the last point: decisions should not be made to deny necessary services based only on abbreviated summaries of medical records.
Our read: an abbreviated case summary is operationally convenient and often defensible on volume grounds. It still cannot substitute for the clinical record when the decision is a denial.
Lesson 4: Care coordination requires more than completed documents
CMS found care coordination activities that did not reflect the enrollee's individual needs or use all available clinical information:
- • Individualized Care Plans that did not address chronic conditions requiring coordination and intervention
- • Missing evidence of Interdisciplinary Care Team coordination
- • Identified needs that never resulted in an implemented care plan
- • Care plans not developed or individualized when the beneficiary could not be reached
CMS's conclusion matters more than the examples: compliance with documentation requirements alone does not demonstrate effective care coordination. Sponsors should audit ICP quality, monitor HRA quality and timeliness, and use available clinical data when enrollee participation in HRAs or ICP development is limited.
Our read: the relevant control is not whether an HRA or ICP exists. It is whether needs identified in the HRA carried into an individualized plan and produced documented coordination. That chain is what the SNPCC protocol tests.
What CMS learned from enforcement evaluations
Enforcement evaluations are not triggered only by program audit referrals. The Division of Compliance Enforcement also receives referrals for noncompliance found during routine monitoring and during financial audits run by CMS's Office of Financial Management.
Lesson 5: Financial protections depend on strong system controls
Configuration failures, data synchronization problems, and payment-integrity weaknesses could cause beneficiaries to pay more than they owed or lose access to covered benefits. CMS notes these errors often reflect a breakdown in operational controls, system testing, or monitoring rather than a misunderstanding of the requirements. Examples:
- • Cost-sharing accumulations not tracked accurately across systems, so enrollees kept paying after reaching their Maximum Out-of-Pocket limit
- • Delays in sharing or updating cost-sharing information across claims platforms, producing charges above MOOP limits
- • Claims and provider payment systems using incorrect payment methodologies, benefit configurations, or provider information
- • Claims systems failing to identify duplicate services, producing duplicate payments and inappropriate cost sharing
- • Eligibility changes processed inaccurately, so claims adjudicated under the wrong benefit or cost-sharing information
- • Claims affected by retroactive Low-Income Subsidy changes not consistently reprocessed
CMS recommends validating cost-sharing calculations and payment methodologies before implementation, regularly testing MOOP and LIS controls, reconciling data after updates and vendor changes, monitoring duplicate charges and refund timeliness, and establishing automated controls that catch discrepancies before they reach beneficiaries.
Our read: these failures tend to affect large populations before anyone notices, which is exactly why CMS calls financial harm one of the most common factors driving enforcement severity. Prevention, exception reporting, reconciliation, and prompt remediation carry more weight here than after-the-fact root-cause analysis.
Lesson 6: Effective monitoring can help reduce enforcement risk
CMS states that the risk of financial penalties increases when a sponsor lacks effective prevention and detection controls and CMS identifies the issue on audit. When analyzing an issue for a CMP, CMS considers whether the sponsor's own monitoring and auditing identified the failure and whether the sponsor responded promptly to remediate affected beneficiaries.
The report's examples: beneficiaries overcharged cost sharing because of undetected configuration errors and therefore never appropriately refunded, and beneficiaries whose claims were inappropriately rejected and who lost timely access to medications treating acute conditions, because sponsors were not monitoring denied claims.
Our read: self-identification does not erase noncompliance. What it does is evidence that the compliance program is functioning and that the sponsor acted before the problem caused additional harm. CMS describes a robust auditing and monitoring program as reflecting a sponsor's good-faith effort to oversee its systems, downstream entities, and benefit structures, and that framing is doing real work in how penalties get sized.
What the CMP numbers show
CMS imposed 14 Civil Money Penalties covering 18 violations and totaling roughly $1.54 million.
| Violation category | Number of violations |
|---|---|
| Beneficiary cost sharing and provider payments | 9 |
| Maximum Out-of-Pocket (MOOP) failures | 6 |
| Low-Income Subsidy processing | 2 |
| Part D medication rejections due to eligibility issues | 1 |
A timing detail worth noting if you are reconciling this against your own records: CMS connects these actions to violations identified through program audits, financial audits, and other routine oversight conducted in 2025, but Appendix B shows the individual penalties were imposed on April 29 and May 1, 2026.
The two largest penalties were CVS Health Corporation at $753,805 and Centene Corporation at $380,785. Twelve additional sponsors received penalties ranging from roughly $10,000 to $84,000.
CMS reports that 89 percent of the violations in the 2025 CMP actions involved enrollees who experienced financial harm greater than $100, and that a single violation can carry more than one aggravating factor. CMS is also explicit that CMP amounts are not meant to reflect a sponsor's overall performance: the calculation weighs the number of affected enrollees, the nature and scope of the noncompliance, and the actual or potential harm that resulted.
Intermediate sanctions in effect during 2025
Intermediate sanctions suspend a sponsor's ability to market to and enroll new members, or to receive payment for new enrollees, and stay in place until the underlying deficiencies are corrected and unlikely to recur. Three categories appear in the report.
Medical Loss Ratio sanctions
Sponsors must generally spend at least 85 percent of premium dollars on enrollee medical care. Missing that threshold for three consecutive years statutorily requires CMS to suspend new enrollment in the noncompliant contract for the subsequent contract year. The report identifies Wellcare of Missouri Health Insurance Company, Inc. as subject to an MLR enrollment suspension effective January 1, 2025, released on August 14, 2025.
D-SNP integration sanctions
Five organizations had D-SNP enrollment sanctions in effect during 2025 because the affected plans lacked fully executed state Medicaid contracts supporting their integration status. Some of the original sanction letters date back to 2020, 2021, and 2022. Four were released in September 2025 once the required state approvals came through, and one affected plan was non-renewed effective December 31, 2025.
Financial solvency sanctions
When a state determines that a sponsor's financial condition requires restrictions on new enrollment, CMS generally imposes parallel enrollment sanctions on the affected MA or Part D contracts. Two sponsors were subject to financial-solvency enrollment suspensions during 2025, eternalHealth, Inc. and Gold Kidney, and both were released during 2025.
What CMS evaluates during program audits
Appendix A summarizes the four core operational areas CMS reviews. Each links to our protocol quick reference below.
| Operational area | What CMS reviews |
|---|---|
| Part D Formulary and Benefit Administration (FA) | Samples of Part D denied claims, to determine how utilization management edits such as prior authorization, step therapy, and quantity limits were applied at the point of sale. Also how non-formulary claims are processed and whether every transition-eligible enrollee received the full transition benefit. |
| Part D Coverage Determinations, Appeals, and Grievances (CDAG) | Compliance with timeframes for processing drug coverage requests, and whether those requests were processed in accordance with 42 CFR 423 Subpart M. |
| Part C Organization Determinations, Appeals, and Grievances (ODAG) | Compliance with timeframes for processing service requests and post-service claims, and whether those requests and claims were processed in accordance with 42 CFR 422 Subpart M. |
| SNP Care Coordination (SNPCC) | Timeliness of Health Risk Assessment completion, whether completed HRAs comprehensively assess enrollee needs, and whether individualized care plans are designed to address the needs the HRA identified. |
Across all four, CMS is evaluating one thing: whether operational controls prevent, detect, and correct noncompliance that affects beneficiaries.
What CMS says to prepare for next
The report's "On the Horizon" section centers on prior authorization, data integrity, interoperability, and governance.
For Medicare Advantage medical items and services subject to prior authorization, the applicable requirements took effect January 1, 2026. Decisions must be made as expeditiously as the enrollee's condition requires, and generally no later than 72 hours for expedited requests and seven calendar days for standard requests.
One clarification the report itself does not make: the seven-calendar-day standard is the part that is new. Under 42 CFR 422.568(b)(1), items and services not subject to the prior-authorization rules in 42 CFR 422.122 still carry the 14-calendar-day standard timeframe. The 72-hour expedited standard in 42 CFR 422.572(a)(1) predates this change.
These requirements do not apply to drugs, which carry their own decision timeframes, and the regulations permit limited extensions in specified circumstances. Consult the cited sections for the precise scope and exceptions rather than working from the report's summary.
CMS says compliance officers should be prepared to demonstrate that their organizations can do three things:
- 1. Prior authorization readiness. Track standard and expedited requests, monitor timeliness, document denial reasons, and escalate cases before CMS timeframes are exceeded.
- 2. Data integrity and interoperability. Keep prior-authorization, appeals, claims, and encounter data consistent across internal systems, delegated entities, and CMS data sources.
- 3. Governance and monitoring. Use compliance oversight activities to test whether operational teams and FDRs are applying requirements consistently and correcting issues before beneficiaries are affected.
CMS is also updating audit protocols to make greater use of existing CMS data. The report says this should reduce duplicative collection but may raise the importance of ensuring submitted data is accurate, complete, and reconcilable to internal systems.
To be clear about what that does and does not say: CMS has not stated that it will cross-check every record against its own data, or that universe submissions are going away. What it signals is that data discrepancies are likely to draw more attention.
The report also lists the two remaining quarterly compliance officer calls: September 15 and November 17.
CMS's practical audit-preparation recommendations
Appendix D recommends that sponsors:
- • Review the CMS Program Audit Process Overview to understand the four stages of an audit
- • Conduct mock audits using the current program audit protocols, including generating and validating universes
- • Review the Integrated Audit Module User Guide in HPMS
- • Review the User Group Resource Document for clarification on the protocols
- • Confirm HPMS contact information is accurate and that staff have system access
- • Ensure staff and delegated entities are familiar with Microsoft Teams, which CMS uses for audit webinars
- • Request a test webinar from the Auditor-in-Charge if access or screen sharing is uncertain
- • Prepare staff to locate requested documentation quickly
- • Review the CDAG and ODAG documentation guidance in HPMS Submission Materials
- • Conduct internal quality reviews so universes match the record layout instructions before submission
- • Contact program area team leads proactively with record layout questions
- • Join audit webinars at least five minutes early
- • Have delegated entities on standby so they can join webinars quickly
- • Review desk-review samples and follow-up questions, and flag missing documents before CMS raises them
The through line: audit readiness is a function of routine operational practice, not of the short preparation window after an engagement letter arrives.
Six control questions to ask now
The six lessons translate into six tests a compliance team can run against its own program. These are our framing, not CMS's.
| Control area | The question |
|---|---|
| System changes | Can we show pre-deployment testing, post-deployment validation, and reconciliation for a recent material change? |
| Delegated oversight | Can we trace one regulatory change through every affected FDR, system configuration, notice template, and monitoring activity? |
| Coverage decisions | Do reviewers receive the complete clinical record needed to decide each request, or an abbreviated summary? |
| Care coordination | Can we demonstrate that needs identified through HRAs produced individualized care planning and documented coordination? |
| Financial protections | Are MOOP, LIS, cost-sharing, duplicate-payment, and refund controls tested across every system that touches them? |
| Self-identification | Can we show that monitoring identified material issues, triggered escalation, documented beneficiary remediation, and addressed root causes? |
Where technology fits
The report describes a connected control environment, where universe validation, guidance management, risk assessment, corrective-action tracking, delegated oversight, and incident documentation reinforce each other. That is the honest case for tooling, and it is worth being precise about what tooling does and does not do.
CMS publishes field-level record layout specifications through the OMB-approved CMS-10717 protocols. Sevana's CMS Universe Scrubber translates those specifications into more than 1,600 discrete validation rules and applies the supported checks to ODAG, CDAG, FA, SNPCC, and COA files before submission. It checks files against the published specifications. It does not perform live reconciliation across your claims, enrollment, and PBM systems, and a file that passes validation is not thereby error-free or compliant. It is a file that no longer fails Sevana's supported checks derived from the CMS specifications.
The rest of the platform supports the surrounding record:
- • Guidance distribution routes HPMS memos and regulatory changes to the people who own them, with acknowledgement on record
- • AI Policy Intelligence surfaces potentially affected policies for your team to review when guidance changes; it does not decide what needs updating
- • Policies and procedures holds versioned policy of record with assigned actions and review history
- • Risk assessment documents identified compliance risks and how they were scored
- • Compliance work plan tracks planned monitoring and corrective work against owners and dates
- • Incident management preserves investigation and remediation evidence
None of these detect an operational failure on their own. A risk register does not notice that a MOOP accumulator drifted, and a work plan does not catch a misconfigured utilization management edit. Detection comes from operational monitoring built into the systems where the work happens. What this software does is make the process repeatable and traceable, so that when CMS asks how a control operates and when you last tested it, the answer is a record rather than a reconstruction.
The bottom line
This report is not mainly a list of obscure regulatory interpretations. Its recurring theme is operational control failure.
A system change was not fully tested. A delegate implemented a requirement inconsistently. A reviewer did not receive complete information. An HRA did not result in an individualized care plan. Financial data did not reconcile across systems. Monitoring did not identify the problem before beneficiaries were harmed.
The question for every sponsor is whether its current controls would catch those same failure patterns before CMS does.
Map the six lessons to your own program
If your team wants to walk through how these six lessons line up with your existing monitoring, delegated oversight, and audit-readiness processes, we are glad to do that. Direct access to the team that builds the product, no SDR gating.
Primary sources
- • CMS, CY 2025 Part C and Part D Program Audit and Enforcement Report (PDF)
- • CMS, Part C and Part D Program Audits
- • 42 CFR 422.122, Prior authorization requirements
- • 42 CFR 422.568, Standard timeframes and notice requirements for organization determinations
- • 42 CFR 422.572, Timeframes and notice requirements for expedited organization determinations
Related Reading
- • The CMS Program Audit: A Complete Guide for Medicare Advantage Plans
- • CMS Enforcement Is Escalating, and Medicare Advantage Plans Should Pay Attention
- • How CMS Ensures Medicare Advantage Plans Stay Compliant
- • The CPE COA Universe: Your Roadmap for the New Discussion-Based Approach
- • Invalid Data Submission (IDS) in 2026: What You Need to Know