HouseH.R. 10636119th Congress

Medicaid Fraud Prevention Act

Full Text

Official text as published. Use Ctrl+F / Cmd+F to search within the document.

[Congressional Bills 119th Congress]
[From the U.S. Government Publishing Office]
[H.R. 10636 Introduced in House (IH)]

<DOC>

119th CONGRESS
  2d Session
                               H. R. 10636

  To amend title XIX of the Social Security Act to require States to 
       conduct fraud risk assessments under the Medicaid program.

_______________________________________________________________________

                    IN THE HOUSE OF REPRESENTATIVES

                           September 28, 2026

    Mr. Rulli (for himself, Mr. Bentz, Mr. Carter of Georgia, Mrs. 
    Fischbach, Mr. Taylor, and Mr. Biggs of Arizona) introduced the 
   following bill; which was referred to the Committee on Energy and 
                                Commerce

_______________________________________________________________________

                                 A BILL

 
  To amend title XIX of the Social Security Act to require States to 
       conduct fraud risk assessments under the Medicaid program.

    Be it enacted by the Senate and House of Representatives of the 
United States of America in Congress assembled,

SECTION 1. SHORT TITLE.

    This Act may be cited as the ``Medicaid Fraud Prevention Act''.

SEC. 2. REQUIRING MEDICAID FRAUD RISK ASSESSMENTS.

    Section 1902 of the Social Security Act (42 U.S.C. 1396a) is 
amended--
            (1) in subsection (a)--
                    (A) in paragraph (89), by striking ``and'' at the 
                end;
                    (B) in paragraph (90), by striking the period at 
                the end and inserting ``; and''; and
                    (C) by inserting after paragraph (90) the following 
                new paragraph:
            ``(91) provide that the State shall comply with the fraud 
        risk assessment requirements under subsection (zz).''; and
            (2) by adding at the end the following new subsection:
    ``(zz) Fraud Risk Assessment Requirements.--
            ``(1) In general.--For purposes of subsection (a)(91), the 
        fraud risk assessment requirements under this subsection are 
        that the State shall--
                    ``(A) not later than 1 year after the date of the 
                enactment of this subsection and not less frequently 
                than annually thereafter, complete a fraud risk 
                assessment as described in paragraph (2);
                    ``(B) not later than 90 days after completing such 
                an assessment, implement a corrective action plan to 
                address any vulnerabilities identified in such 
                assessment that includes measurable outcomes and 
                specific deadlines with respect to the completion of 
                corrective actions under such plan; and
                    ``(C) not later than 1 year after the completion of 
                the first fraud risk assessment under this subsection, 
                and annually thereafter, submit to the Secretary a 
                report that includes the information specified in 
                paragraph (3) with respect to the preceding year.
            ``(2) Fraud risk assessment described.--
                    ``(A) In general.--For purposes of paragraph (1), a 
                fraud risk assessment described in this paragraph is a 
                comprehensive assessment of fraud risks across all 
                components of the State plan (and any waiver of such 
                plan), including with respect to medical assistance 
                provided on a fee-for-service basis, medical assistance 
                provided through a managed care entity, and eligibility 
                determination and enrollment systems (including systems 
                operated by or on behalf of the State for the purposes 
                of eligibility verification and redetermination) under 
                such plan (or waiver), that--
                            ``(i) to the extent practicable, uses data 
                        from existing Federal and State program 
                        integrity systems, including--
                                    ``(I) the Payment Error Rate 
                                Measurement program (or any successor 
                                program);
                                    ``(II) the Transformed Medicaid 
                                Statistical Information System (or any 
                                successor system);
                                    ``(III) managed care encounter 
                                data;
                                    ``(IV) data from a State medicaid 
                                fraud control unit (as defined in 
                                section 1903(q)) or another program 
                                integrity activity;
                                    ``(V) the Public Assistance 
                                Reporting Information System (PARIS) 
                                (or any successor system); and
                                    ``(VI) beginning October 1, 2029, 
                                the system established by the Secretary 
                                under subsection (uu);
                            ``(ii) identifies and ranks the most 
                        significant fraud, waste, and abuse 
                        vulnerabilities of such plan (or waiver);
                            ``(iii) estimates the amount that could 
                        potentially be improperly expended under such 
                        plan (or waiver) due to each such 
                        vulnerability, including any improper payments 
                        associated with each such vulnerability, with 
                        respect to, at minimum, the 12-month period 
                        beginning on the date on which such assessment 
                        is completed;
                            ``(iv) evaluates the effectiveness of 
                        existing program integrity tools under such 
                        plan (or waiver);
                            ``(v) identifies gaps in data sharing, 
                        oversight, and enforcement with respect to 
                        fraud, waste, and abuse under such plan (or 
                        waiver); and
                            ``(vi) follows the guidelines established 
                        by the Secretary under subparagraph (B).
                    ``(B) Establishment of guidelines.--Not later than 
                January 1, 2027, the Secretary shall establish 
                guidelines that--
                            ``(i) identify and define standardized 
                        categories of fraud, waste, and abuse risk 
                        across State plans (and waivers of such plans), 
                        including with respect to eligibility 
                        determinations, provider enrollments, claims 
                        processing, and managed care;
                            ``(ii) establish criteria for the 
                        identification, scoring, and prioritization of 
                        categories of risk identified under clause (i) 
                        on the basis of the likelihood of such risks 
                        and estimates of potential improper 
                        expenditures (as described in subparagraph 
                        (A)(iii)) due to such risks; and
                            ``(iii) enable fraud risk assessments 
                        completed under this subsection by different 
                        States to be effectively compared.
            ``(3) Information specified.--For purposes of paragraph 
        (1), the information specified in this paragraph is--
                    ``(A) the results of any fraud risk assessments 
                conducted under paragraph (1)(A);
                    ``(B) the most significant fraud, waste, and abuse 
                vulnerabilities identified under such assessments;
                    ``(C) the potential improper expenditures (as 
                described in paragraph (2)(A)(iii)) estimated under 
                such assessments;
                    ``(D) corrective actions taken or planned to be 
                taken under paragraph (1)(B) with respect to such 
                vulnerabilities; and
                    ``(E) an explanation of any progress made in 
                addressing such vulnerabilities.
            ``(4) Annual report to congress.--Not later than 1 year 
        after the date on which the first report under paragraph (1)(C) 
        is submitted to the Secretary, and annually thereafter, the 
        Secretary shall submit to Congress a report that, with respect 
        to the preceding year--
                    ``(A) analyzes the findings from reports submitted 
                to the Secretary under such paragraph;
                    ``(B) identifies national trends with respect to 
                Medicaid fraud risk;
                    ``(C) evaluates State implementation of corrective 
                action plans implemented under paragraph (1)(B); and
                    ``(D) includes recommendations for legislative or 
                administrative action to address fraud, waste, and 
                abuse vulnerabilities identified in such reports.''.
                                 <all>