The GAO annual number for federal improper payments is $233 billion. It is repeated in every RFP, every vendor pitch, every congressional hearing. What is almost never said next: who inside the government actually owns recovering it, what tools they already have, and what a new investment actually changes. This is written for the program managers and payment-integrity leads working inside CMS, VA, DoD, and state Medicaid agencies. Not the vendors selling to them.
The playbook is the same in structure regardless of which program you run: measure your improper payment rate accurately, identify where the leakage concentrates, deploy pre-payment controls where you can catch errors cheaply, and run post-payment recovery on what slips through. The tools change. The framework does not.
1. The $233B GAO number and where it actually lives
The $233B headline number includes non-healthcare programs: EITC, unemployment insurance, SNAP, and others. The healthcare portion, roughly $80 to $100 billion depending on the year, sits mostly in Medicare FFS, Medicare Advantage, Medicaid, and CHIP, with smaller but meaningful exposure in VA and DoD (TRICARE) direct-care programs. A payment integrity lead inside any one of these programs sees a piece of that number, never the whole thing.
The distinction matters because the interventions that reduce Medicare FFS improper payments (RAC audits, prior authorization, medical necessity edits) do not map cleanly to Medicaid (state-federal cost sharing, MMIS variation, TPL complexity) or VA (integrated delivery model, VA-run direct care alongside Community Care contracts). Program-specific strategy beats one-size-fits-all payment integrity strategy every time.
2. Fraud, waste, and abuse (and why the distinction matters)
Federal payment integrity uses three overlapping terms with legal and operational consequences. Confusing them wastes investigator time and misroutes cases.
The enforcement path matters. Fraud cases go to DOJ and take years. Waste and abuse cases stay administrative, recover money faster, and preserve provider relationships. Miscategorizing an administrative case as fraud triggers a chain of legal review that costs the agency months. Miscategorizing fraud as abuse means the case walks through overpayment recovery and never gets the criminal referral it deserved.
3. Improper payment rates by program
4. PIIA and the reporting scaffold
The Payment Integrity Information Act of 2019 (PIIA) is the current statutory framework for federal payment integrity reporting. It replaced the earlier IPIA (2002), IPERA (2010), and IPERIA (2012). Every federal agency with a program susceptible to significant improper payments has PIIA obligations:
- Identify high-risk programs. Any program with estimated improper payments over $10 million or 1.5 percent of program outlays must be flagged for testing.
- Estimate and report the rate annually. The methodology has to be statistically valid, sampled from a representative population, and independently verifiable.
- Publish a corrective action plan for programs exceeding thresholds. Program with rate above 10 percent triggers additional OMB oversight and mandatory CAP documentation.
- Report progress and results to OMB and Congress. Annual Agency Financial Report, PaymentAccuracy.gov data upload, and OMB-A-136 disclosures.
For a payment integrity lead inside an agency, PIIA is the operating rhythm. The measurement methodology, the sample selection, the analytics that produce the rate, the CAP documentation that responds to findings above threshold. Every payment integrity tool investment ultimately has to serve one of these four obligations, or it is not funded.
5. Pre-payment integrity: what actually stops the check
Pre-payment integrity is cheaper per dollar prevented than post-payment recovery. Every dollar caught before it leaves the treasury is a dollar that does not need to be chased through overpayment demands, appeals, and collections. Mature programs push as much as they can to the pre-payment side.
Automated claim edits
The oldest and most cost-effective pre-payment tool. NCCI (National Correct Coding Initiative) edits, MUE (Medically Unlikely Edit), LCD (Local Coverage Determination) enforcement, and payer-specific rule sets that reject claims failing basic coding logic before adjudication. Every federal claims processor runs some version of this. The differentiator between agencies is edit freshness and how quickly new rules propagate.
Prior authorization
Pre-service medical necessity review. CMS-0057-F (effective January 1, 2026) restructured the Medicare Advantage prior authorization process. See our prior authorization automation pillar for the full mechanics. Prior auth catches high-dollar services before they render, which is where the pool concentrates.
Medical necessity screening
Post-adjudication but pre-payment review of high-risk claims. Automated flagging of claims meeting statistical outlier criteria (unusual code combinations, coding patterns inconsistent with diagnosis, provider outlier status) with human review before payment release. Slows payment for a small percentage of claims but catches errors that would otherwise require post-payment recovery.
Coverage and eligibility verification
Confirming the beneficiary was actually eligible for the service on the date of service, in the correct plan, with active coverage. Simple in Medicare FFS. Complex in Medicaid where eligibility churn is monthly. The single largest driver of Medicaid improper payments is eligibility misapplication caught after the fact.
6. Post-payment integrity: RAC, UPIC, ZPIC, SIU
Everything that gets through pre-payment lands here. The post-payment integrity landscape is a mix of contractor programs and agency direct-run investigations.
7. The payment integrity software market
Four functional software categories dominate procurement in federal payment integrity. Most agencies run at least two, usually with legacy modernization gaps between them.
Pre-payment claim editors
Rule-based edit engines that fire before adjudication. Vendors: SAS Fraud Framework, LexisNexis Risk Solutions, Optum Payment Integrity, Cotiviti Payment Integrity. Sold to CMS, state Medicaid, TRICARE. Long implementation cycles, deep integration with claims processing.
Post-payment analytics platforms
Pattern-detection engines that identify anomalies for post-payment review. Vendors: Guidehouse (formerly Navigant), Cotiviti, HMS, Change Healthcare Payment Integrity. Deploy against completed claims databases, surface leads for human investigator review.
Case management systems
Track SIU investigations from lead through resolution. Vendors: Salesforce Public Sector Solutions, ServiceNow, Appian, and legacy custom builds still running at many state agencies. Increasingly integrated with the analytics platforms upstream.
AI-enabled anomaly detection
Newer category. Palantir Foundry has significant footprint in federal healthcare payment integrity. Databricks-based custom builds are common at state Medicaid. Cohere Health, Alignment Health, and several smaller vendors sell into MAC and MCO SIU teams. The differentiation is unstructured data handling: reading clinical narratives, medical records, and provider notes at scale rather than only claim-level structured data.
8. Where AI actually helps
Anomaly detection at scale
The historical approach to identifying suspicious billing patterns was rule-based: build a rule for each pattern you already know about. AI-enabled detection surfaces patterns nobody had thought to write a rule for, from behavioral clustering across providers, beneficiaries, or geographic areas. Especially useful for emerging fraud schemes where the pattern is novel.
Document processing on medical records
When a post-payment audit demands medical records, the reviewer has to read every page and match it against the billed CPT. AI can pre-process the record, extract the referenced clinical elements, flag documentation gaps, and hand the reviewer a scored packet instead of raw pages. Cuts review time per case 60 to 80 percent.
Case triage and routing
Every SIU has more leads than investigators. AI-enabled triage scores incoming leads (tips, referrals, anomaly hits, whistleblower complaints) by likely case merit and dollar value at risk, routes to the right investigator by jurisdiction and current caseload, and closes leads unlikely to yield findings without consuming investigator time.
Provider outlier detection with contextual scoring
Outlier detection historically flagged every 2-standard-deviation provider as suspicious. AI-enabled versions apply contextual scoring: is the outlier a rural provider with legitimate case-mix reasons for higher billing, or a metropolitan provider with no clinical rationale for the pattern. Cuts false-positive rate substantially.
9. Five metrics program managers actually track
- Program improper payment rate. The PIIA number. Reported annually, benchmarked against target. Historical trend line is what OMB actually looks at.
- Dollars prevented (pre-payment). Sum of claim adjustments made pre-payment. Attribution to specific edit rules or analytics pipelines lets you show which controls are earning their keep.
- Dollars recovered (post-payment). Sum of overpayment recoveries from RAC, TPE, SMRC, UPIC, MFCU, and internal SIU. Track by program and by contractor.
- Cost per dollar recovered. Contractor fees plus internal labor per dollar recovered. Under $0.10 per dollar recovered is best-in-class; over $0.30 is a program that needs restructuring.
- SIU case throughput and yield. Number of cases opened, closed, and referred per investigator FTE per year, weighted by dollar recovery. Reveals whether the SIU is scaling with the workload or falling behind.
10. Where to start if you inherited a program
- Read the last three years of your Agency Financial Report improper payment section. Look at the trend line, the CAP commitments, and whether previous commitments were actually met. This tells you what OMB is watching.
- Map your current pre-payment controls. What edits fire before adjudication? Who owns updating the rule set? How often does the rule set get refreshed? If refresh cadence is longer than quarterly, you are behind on emerging patterns.
- Map your post-payment contractor relationships. Which RACs, TPEs, SMRCs, and UPICs are active on your program? What is each recovering, and at what cost? Contingency-based contractors have different economics than fixed-price contractors.
- Audit your SIU intake workflow. How do leads arrive? How are they scored? How many are open right now? What is the average time from open to disposition? SIU backlog is the biggest hidden risk in most agency payment integrity operations.
- Look at your data infrastructure. Are claims, provider, beneficiary, and enrollment data joinable in one analytic environment? If not, this is what to fix before any AI tooling investment.
Payment integrity workflows for federal programs, built on FedRAMP-authorized infrastructure.
BetaQuick builds AI-enabled payment integrity workflows for federal healthcare programs on FedRAMP-authorized Amazon Bedrock in AWS GovCloud. Anomaly detection, document processing, and case triage that fits inside your existing PIIA reporting scaffold and integrates with your SIU case management system. Public Trust cleared, SAM.gov active, small business.
Book a scoping call →11. Frequently asked questions
Want to talk through this for your program specifically?
A 30-minute call. Bring your program name, your current improper payment rate, and one bottleneck in your pre-payment or post-payment workflow. We will tell you what a first-cycle audit would surface, what an AI-enabled workflow would look like on FedRAMP-authorized infrastructure, and whether we are the right partner. Public Trust cleared, SAM.gov active. No slides, no pitch.
Book a 30-minute consult →