What just happened.
The most aggressive Medicare enforcement action in history is happening right now. Home health and hospice are at the top of the target list. If you follow CMS bulletins closely, you already know most of this. If you have been heads-down on your own agency and only catching headlines, here is what you need to know today.
These are not adjacent trends. They are coordinated. The enrollment freeze buys CMS six months of enforcement bandwidth with no new provider onboarding to distract. The state audit order pulls a companion enforcement track through Medicaid. The DOJ division adds criminal exposure to what used to be civil compliance issues. The AI enforcement platform scales the whole thing to every provider in the country simultaneously.
Why this is the new normal.
The temptation for agency owners is to treat this like a squeeze that will pass. It will not. Three structural changes make 2026 enforcement fundamentally different from prior cycles.
First: the AI scale.
CMS is no longer sampling. Their algorithms scan every claim, every provider, every billing period. In the pre-AI era, a small agency could reasonably assume their claims would never be individually reviewed unless something triggered attention. That assumption is gone. Every claim now moves through pattern-detection algorithms that compare your billing to regional and national benchmarks in near real-time. The algorithm does not need to open the visit notes to flag you. It just needs your billing pattern to look anomalous.
Second: the criminal exposure.
Before this year, a missing physician signature on a plan of care meant a denied claim. In some agencies it meant a repeat-education letter. Now it can mean a fraud referral. CMS sent 372 referrals to the DOJ last year covering $3.7 billion. The new National Fraud Enforcement Division is staffed to handle more. The gap between "compliance issue" and "criminal allegation" is thinner than it has ever been, and the DOJ's charging patterns show they are less inclined than in prior years to treat documentation gaps as civil-only matters.
Third: the enrollment leverage.
The enrollment moratorium changes the negotiating position between agencies and CMS. Under normal conditions, an agency that gets revoked could restructure, re-enroll under a new TIN, and resume operations. During the moratorium, that path is closed for home health and hospice specifically. Revocation now carries a genuine finality it did not carry before. CMS knows this. Providers under investigation know this. The leverage tilts toward the agency getting the compliance right the first time, not remediating after the fact.
The combination of these three changes is why 2026 is not a squeeze to weather. It is a permanent shift in what running a home health agency requires on the compliance side.
How CMS's AI enforcement architecture works.
Understanding what CMS's algorithms actually look at matters, because it determines what your agency needs to monitor internally. Three layers.
Layer 1: pattern outlier detection
Every home health agency's billing pattern is compared against regional and national benchmarks continuously. The variables that get watched are not secret; CMS has been publishing them for years:
- Episode count per patient
- LUPA (Low Utilization Payment Adjustment) rate vs regional average
- Therapy visits as a share of total visits
- Case-mix weight distribution vs peer agencies in the same geography
- Primary diagnosis distribution vs peer agencies
- Recertification rate
- Discharge status distribution
An agency whose numbers on any of these look significantly different from peer agencies in the same MSA gets flagged. Both high-side and low-side outliers get flagged. High therapy utilization can indicate upcoding for reimbursement. Low LUPA rates can indicate the same. Unusually low outlier rates can indicate the same. The algorithms are looking for statistically anomalous behavior in any direction.
Layer 2: intra-claim consistency checking
For claims that pass layer 1 or are pulled for other reasons, the second layer checks internal consistency. Does the OASIS support the case-mix group billed? Does the plan of care include the services rendered? Does the visit note support the level of skilled care documented? Does the F2F encounter documentation establish homebound status? Does the physician signature date precede the first billable visit? These checks are largely rule-based and highly automatable. Every inconsistency generates a flag.
Layer 3: cross-provider pattern matching
The third layer looks across providers for patterns that suggest coordinated activity. Referral pattern clusters (a small group of physicians sending high volumes to a small group of agencies), patient overlap between agencies that should not have geographic overlap, and shared ownership patterns that were not disclosed on enrollment. This layer is where fraud referrals usually originate; the first two layers surface compliance issues, the third surfaces schemes.
Most agencies do not need to worry about layer 3. But layers 1 and 2 are the ones that will catch a well-intentioned agency with drift in its documentation practices, and those are the ones worth monitoring internally.
The five things CMS is looking for.
Every audit finding, every fraud referral, every revocation traces back to a small number of pattern categories. Focus your compliance attention here.
What happens when CMS sends an ADR.
Additional Documentation Requests are the mechanic by which CMS moves from "your agency looks anomalous" to "prove these specific claims." Understanding the ADR process is essential because agencies that mishandle ADRs turn what should be a documentation issue into an escalation cascade.
The ADR window is 45 days.
Once CMS issues an ADR, the agency has 45 calendar days to submit the requested documentation. Miss the deadline and the claims are automatically denied for insufficient documentation. Submit incomplete documentation and they are denied on medical necessity or plan-of-care grounds. Submit documentation that is inconsistent with the OASIS or the billed claim and the denial escalates to a broader review.
What actually gets requested.
A typical home health ADR requests the following for each selected claim: OASIS assessment (start of care and any subsequent), signed plan of care (485), F2F encounter documentation, physician orders including verbal orders and telephone orders, all visit notes for the episode, medication reconciliation, discharge summary if applicable, and any supporting clinical documentation. That is a substantial package per claim. If the ADR covers 10 claims, that is 10 complete records assembled in 45 days.
What kills agencies.
Not the ADR itself. What kills agencies is (a) discovering during ADR preparation that the physician never signed a plan of care they thought was signed, (b) discovering that the OASIS on file does not match what was billed, or (c) discovering that visit notes were never completed for visits that were billed. The ADR does not create these problems; it just surfaces them under a deadline.
Escalation path.
Persistent ADR failures escalate. First to Targeted Probe and Educate (TPE), where a Medicare Administrative Contractor selects 20-40 claims for pre-payment review over multiple rounds. Then to Unified Program Integrity Contractor (UPIC) review, which is a deeper investigation. Then to program integrity referrals that can include recoupment, penalties, revocation, and in serious cases fraud referral to the DOJ. The 2026 environment tightens each of these escalation steps.
How to run a self-audit today.
The goal of a self-audit is to know your exposure before CMS does. Not to fix everything (impossible in most agencies). To know where you stand so you can prioritize remediation and be ready if CMS knocks.
Step 1: Pull 30 to 60 days of recent claims.
Include the 837 file, the associated OASIS assessments, the plans of care with signature dates, visit notes for the sampled episodes, and F2F encounter documentation. Any of the major home health EHRs (Homecare Homebase, WellSky, KanTime, MatrixCare, Netsmart, Axxess) can export this data.
Step 2: Check each claim against the five categories.
OASIS internal consistency (do functional scores match narratives?). Signature compliance (did the physician sign the 485 before the first billable visit?). PDGM coding (does the clinical grouping match the primary diagnosis?). Billing pattern (are your utilization patterns within a reasonable band vs regional norms?). Medical necessity (do visit notes establish homebound status and skilled need?).
Step 3: Compare your billing patterns to regional benchmarks.
Publicly available Medicare data (available through CMS's data.gov endpoints and multiple third-party analytics platforms) lets you see how your agency's episode counts, LUPA rates, therapy-to-nursing ratios, and case-mix distributions compare to peer agencies in your MSA. If you are significantly high or low on any of these, understand why before CMS asks.
Step 4: Score your risk in three categories.
Green = documentation supports the claim, patterns are within peer norms, no material gaps. Yellow = minor documentation gaps that would survive an ADR but not an in-depth audit; patterns near the edge of peer norms. Red = material documentation gaps (missing signatures, inconsistent OASIS, absent F2F); patterns significantly outside peer norms. Do the red items first. Fix the yellow items over the next 60-90 days.
Step 5: Assemble your ADR-ready package process.
Even if you find nothing wrong in Steps 1-4, build the process for pulling ADR-ready documentation packages before you need it. Which staff pull records, in what format, on what timeline, with what quality check. Agencies that scramble to pull records post-ADR routinely miss the deadline or submit incomplete packages that turn a 10-claim ADR into a broader review.
Tools and stack.
Three categories of tools exist for home health compliance monitoring. Each solves a piece.
EHR-native compliance modules
Homecare Homebase, WellSky, KanTime, MatrixCare, Netsmart, and Axxess all include compliance and quality assurance modules. These are strong on workflow enforcement (blocking claim submission before signatures) and on standard reports. They are weak on billing pattern analytics vs regional benchmarks and on cross-episode consistency checking. Necessary but not sufficient.
Third-party billing and coding auditors
Specialized firms offer periodic manual audits of coding accuracy, OASIS accuracy, and documentation completeness. These provide deep review of sampled claims and remediation guidance. The limitation is coverage: manual audits sample a small percentage of claims, and the gap between one audit and the next is the window where drift accumulates.
AI-native compliance monitoring
The category emerging in 2026 in response to CMS's own AI enforcement. An AI agent reads every claim as it moves through the workflow, checks OASIS consistency, signature compliance, PDGM coding, billing pattern anomalies, and medical necessity documentation, and flags exceptions before submission. The advantage is coverage (every claim, not a sample) and speed (real-time, not quarterly). The limitation is that these tools are new; buyer due diligence on any specific vendor is essential.
Most compliant agencies in 2026 will run a combination: EHR-native for workflow enforcement, periodic third-party audit for depth on sampled claims, and AI-native monitoring for coverage across all claims. No single tool covers everything.
The 30-day action plan.
If you have read this far and want to actually move, here is what to do in the next 30 days.
- Week 1: Pull the data. Export 30-60 days of claims, OASIS, and plans of care from your EHR. Assign one owner (compliance officer, DON, or agency owner) to hold the self-audit process.
- Week 2: Run the five-category check. Sample 20-30 recent episodes. Check each against OASIS consistency, signature compliance, PDGM coding, billing pattern, medical necessity. Document findings in a simple red/yellow/green scoring sheet.
- Week 3: Compare patterns to peers. Pull public Medicare data for your MSA. Compare your episode counts, LUPA rates, therapy ratios, and case-mix distribution to peer agencies. Note anything that looks outlying.
- Week 4: Build the ADR-ready process. Document exactly which staff pull records for an ADR, in what format, on what timeline. Run a dry-run: pull a complete ADR package for one claim and time the process. If it takes more than 2-3 hours, the process needs redesign before a real ADR arrives.
None of this requires new software or new hires. It requires deciding it is worth 30 days of attention. Given what is happening at CMS, it almost certainly is.
Frequently asked.
Yes. On May 13, 2026, CMS implemented a six-month nationwide moratorium on new Medicare enrollments for Home Health Agencies and Hospices. The freeze focuses CMS enforcement resources on existing providers while intensified audits and revalidations run.
Five categories: OASIS inconsistencies (scores vs narratives, GG items, E2 compliance), unsigned/late-signed plans of care (the #1 audit finding), PDGM coding anomalies, billing pattern outliers (episode count, LUPA rate, therapy ratio vs peers), and medical necessity documentation gaps.
Yes. FY 2025 program integrity savings hit $41.9 billion, up 59% YoY, with CMS explicitly crediting AI and advanced data analytics. Every provider's billing pattern is scanned continuously against regional and national benchmarks.
45 days to submit documentation (OASIS, plan of care, F2F, physician orders, all visit notes, medication reconciliation, discharge summary). Miss the deadline = automatic denial. Submit incomplete = medical necessity denial. Escalation path: TPE → UPIC → program integrity referral.
CMS ordered every state Medicaid agency to audit providers and submit new revalidation strategies. Home health is at the top of the target list in most states. Same OASIS, plan-of-care, and billing pattern issues that fail Medicare audits also fail state Medicaid audits.
Three structural changes: AI scale (no more sampling, every claim scanned), criminal exposure (missing signatures can trigger fraud referrals, not just denials), enrollment leverage (revocation is now genuinely final for home health during the moratorium).
Run a self-audit on 30-60 days of recent claims against the five categories. Assemble your ADR response process before you need it. Get an outside read on your billing patterns vs regional benchmarks. Our free 15-minute snapshot delivers all three.
Free 15-minute Zoom meeting. Send us 30 days of claims data and our AI agent scans it against the same audit criteria CMS uses. You leave the call knowing where you stand.
