MES Certification Navigator
PE

Determine Adverse Action Incident

Compliance Management

Description

The Determine Adverse Action Incident business process receives an incident from an investigative unit with the direction to pursue the case to closure. The case may result in civil or criminal charges, corrective action, removal of a provider, contractor, trading partner or member from the Medicaid Program, or the State Medicaid Agency (SMA) may terminate or suspend the case. Individual state policy determines what evidence is necessary to support different types of cases: • Provider utilization review • Provider compliance review • Contractor utilization review (includes managed care organizations) • Contractor compliance review • Member utilization review • Investigation of potential fraud or abuse review • Drug utilization review • Quality review (e.g., Consumer Assessment of Healthcare Providers and Systems (CAPHS) and Healthcare Effectiveness Data and Information Set (HEDIS) measures) • Performance review (e.g., Key Performance Indicator (KPI)) • Contract review • Erroneous payment review • Audit Review • Other evaluation of information Different criteria and rules, relationships, and information define each type of adverse action incident and require different types of external investigation.

Business Process Template

Trigger events
Environment-based
  • Request to investigate adverse action incident.
  • Receive requests for suppression of information or corrective action from federal and state law enforcement.
  • Receive compliance investigation information from Centers for Medicare & Medicaid Services (CMS).
  • Receive compliance investigation information from Medicaid Fraud Control Unit (MFCU).
  • Receive compliance investigation information from Office of Inspector General (OIG).
  • Receive self-disclosure of actual or potential violations from provider.
Interaction-based
  • Receive alert from Manage Compliance Incident Information business process for further investigation.
Results
  • Monitored adverse action incident and tracked activities.
  • Determination of disposition and closure of incident.
  • If applicable, alert sent to notify member via Manage Applicant and Member Communication business process of incident tracking information.
  • If applicable, alert sent to notify provider via Manage Provider Communication business process of incident tracking information.
  • If applicable, alert sent to notify contractor via Manage Contractor Communication business process of incident tracking information.
  • If applicable, alert sent to Disenroll Member business process to remove member from services.
  • If applicable, alert sent to Disenroll Provider business process to remove provider from services.
  • If applicable, alert sent to Terminate Provider business process to cease activities with provider.
  • If applicable, alert sent to Close Out Contract business process to cease activities with contractor.
  • If applicable, notification sent to state or federal law enforcement agencies of possible criminal investigation.
  • If applicable, notification sent to CMS for compliance investigation.
  • If applicable, notification sent to MFCU of compliance investigation.
  • If applicable, notification sent to OIG of compliance investigation.
  • Tracking information as needed for measuring performance and business activity monitoring.
Business process steps
  • 1. START: Receive request to investigate adverse action incident.
  • 2. Assign and authorize an adverse action incident manager to manage an incident and request additional information.
  • 3. Establish adverse action incident case with required information.
  • 4. Examine information associated with the case, and request more historical information as needed.
  • 5. Determine action to take (e.g., journal entry, appointment scheduling, research, communication).
  • 6. Perform appropriate action.
  • 7. Correspond with providers, members, agents, guardians, attorneys, and others to notify them regarding the investigation, their rights, and the right of the SMA to request documentation.
  • 8. If applicable, send alert to notify member via Manage Applicant and Member Communication business process of incident tracking information.
  • 9. If applicable, send alert to notify provider via Manage Provider Communication business process of incident tracking information.
  • 10. If applicable, send sent to notify contractor via Manage Contractor Communication business process of incident tracking information.
  • 11. Conduct inquiries and investigations. Depending on the type of case, the SMA may need to conduct different external inquiries (e.g., view medical records, interview members, validate credentials).
  • 12. Document evidence as required.
  • 13. When research and analysis are complete, report the case disposition (e.g., cancel incident, claim damages, identify corrective action, suspend or terminate participation in Medicaid Program).
  • 14. If applicable, send alert to Disenroll Member business process to remove member from services.
  • 15. If applicable, send alert to Disenroll Provider business process to remove provider from services.
  • 16. If applicable, send alert to Terminate Provider business process to cease activities with provider.
  • 17. If applicable, send alert to Close Out Contract business process to cease activities with contractor.
  • 18. If applicable, send notification to state or federal law enforcement agencies of possible criminal investigation.
  • 19. If applicable, send notification to CMS for compliance investigation.
  • 20. If applicable, send notification to MFCU of compliance investigation.
  • 21. If applicable, send notification to OIG of compliance investigation.
  • 22. END: Close adverse action incident.
Predecessor processes
Shared data
  • Member data store including demographics, eligibility, enrollment, and grievance information
  • Provider data store including provider network, contract, and grievance information
  • Contractor data store including provider network, and contract information
  • Claims data store including payment information
  • Financial data store including accounts receivable and accounts payable information
  • Business Activity data store including performance information
  • Compliance Management data store including compliance incident information
Constraints

States and programs within States establish different criteria for their investigations. Rules change along with the experience of the state, health care best practices, modifications in benefits, and with the addition of new provider and member types.

Failures
  • No request to investigate adverse action incident received.
  • Ceased incident without reaching disposition.
Performance measures
  • Time lag between request for documents and receipt = __ Days, __ Hours
  • Time to bring a case to closure = __ Months, __ Weeks
  • Number of cases that the agency is able to close within designated time period = ___
  • Percent cases closed without grievance or appeal = ___%

Source: CMS MITA 3.0 Business Process Template, Performance Management BPT.pdf, pages 8-12.

Business Capability Model (11 questions)

Each capability question defines five maturity levels, from Level 1 through Level 5.

Business Capability Descriptions

How integrated or central is the process?
  1. LEVEL 1The duplicate process is in multiple parts of the organization. There is little coordination among SMA programs or between SMA and other stakeholders (e.g., other state agencies, CMS, intermediaries, other payers) in relation to the process.
  2. LEVEL 2SMA integrates the process within SMA. SMA improves coordination between SMA and other stakeholders.
  3. LEVEL 3SMA fully integrates the process with state and federal law enforcement, CMS, and intrastate agencies to the extent possible within the intrastate.
  4. LEVEL 4SMA fully integrates the process with state, district, and federal law enforcement, CMS, and interstate agencies to the extent possible within the region.
  5. LEVEL 5SMA fully integrates the process with state, district, and federal law enforcement, CMS, and other federal agencies to the extent possible across the nation.
Is the process primarily manual or automatic?
  1. LEVEL 1The process consists primarily of manual paper-based activity to accomplish tasks.
  2. LEVEL 2SMA uses a mix of manual and automatic processes to accomplish tasks.
  3. LEVEL 3SMA automates process with state and federal law enforcement, CMS, and intrastate agencies to the full extent possible within the intrastate. SMA produces audit trail of adverse action decision 100% of the time.
  4. LEVEL 4SMA automates process with state, district, and federal law enforcement, CMS, and interstate agencies to the full extent possible across the interstate.
  5. LEVEL 5SMA automates process with state, district and federal law enforcement, CMS, and other federal agencies to the full extent possible across the nation.
Does the State Medicaid Agency use standards in the process?
  1. LEVEL 1SMA focuses on meeting compliance thresholds for state and federal regulations using state-specific standards.
  2. LEVEL 2SMA applies a mix of HIPAA and state-specific standards.
  3. LEVEL 3SMA adopts MITA Framework, industry standards, and other nationally recognized standards for exchange of information with state and federal law enforcement, CMS, and intrastate agencies.
  4. LEVEL 4SMA adopts MITA Framework, industry standards, nationally recognized standards for exchange of information with state, district, and federal law enforcement, CMS, and interstate agencies.
  5. LEVEL 5SMA adopts MITA Framework, industry standards, and other recognized standards for exchange of information with state, district, and federal law enforcement, CMS, and other federal agencies.
How does the State Medicaid Agency collaborate with other agencies or entities in performing the process?
  1. LEVEL 1Very little collaboration occurs with other agencies to standardize information exchange or business tasks.
  2. LEVEL 2SMA collaborates with other agencies and entities to adopt HIPAA standards and Electronic Data Interchange (EDI) transactions.
  3. LEVEL 3SMA collaborates with other intrastate agencies and entities to adopt national standards, and to develop and share reusable business services with state and federal law enforcement, CMS, and intrastate agencies.
  4. LEVEL 4SMA collaborates with other interstate agencies and entities to adopt national standards, and to develop and share reusable processes with state, district, and federal law enforcement, CMS, and interstate agencies.
  5. LEVEL 5SMA collaborates with agencies and entities for national (and international) interoperability improvements that maximize automation of routine operations.

Business Capability Quality: Timeliness of Process

How timely is the end-to-end process?
  1. LEVEL 1Process meets threshold or mandated requirements for timeliness (i.e., the process achieves results within the time specified by law or regulation). Case management is primarily a manual process including a desk review of medical records and evidence, request for additional data, on-site audit of provider location, and final disposition and reporting. The process requires three (3) months or more from the time SMA identifies the case.
  2. LEVEL 2Process timeliness improves through use of automation. Timeliness exceeds legal requirements. From the time SMA identifies a case, the process completes in two (2) months or less.
  3. LEVEL 3Timeliness improves via state and federal collaboration, use of information sharing, standards, and regional information exchange hubs. Timeliness exceeds Level 2.The process requires1 month or less to reach resolution. SMA distributes Notice of appeal rights within 15 minutes or less 100% of the time.
  4. LEVEL 4Information is available in near real time. Processes that use adverse action incident information result in immediate action, response, and results. SMA has interstate interoperability, which further improves timeliness over Level 3.
  5. LEVEL 5Information is available in real time. Processes improve further through connectivity with other States and with federal agencies. Most processes execute at the point of service. Results are almost immediate.

Business Capability Quality: Data Access and Accuracy

How accurate is the information in the process?
  1. LEVEL 1Use of direct data entry for information collection is manually intensive and susceptible to inconsistent or incorrect information. Stakeholders are unable to rely on information for decision-making.
  2. LEVEL 2HIPAA standard transactions improve accuracy of information but the decision-making process may be erroneous or misleading. Accuracy is higher than at Level 1.
  3. LEVEL 3Automation of information collection increases the reliability of SMA’s internal information. External sources of information use MITA Framework and industry standards for information exchange. Decision-making is automatic using standardized business rules definitions. Accuracy rating is at 99% or higher.
  4. LEVEL 4Automation of information collection increases the reliability of SMA’s internal and external sources of information. SMA adopts MITA Framework and industry standards for information exchange with interstate agencies. Decision-making is automatic using regional standardized business rules definitions s. Accuracy rating is at 99% or higher.
  5. LEVEL 5SMA adopts MITA Framework and industry standards for information exchange with national agencies. Decision-making is automatic using national standardized business rules definitions. Accuracy rating is at 99% or higher.
How accessible is the information in the process?
  1. LEVEL 1SMA stores information in disparate systems including paper storage and obtains information manually. SMA has limited access to data because of is inconsistent and untimely receipt of information. Data acquisition to support the case may take 60 business days or more.
  2. LEVEL 2SMA stores information in disparate systems, but automation and HIPAA standards increase accessibility over Level 1.
  3. LEVEL 3SMA obtains information easily and exchanges with state and federal law enforcement, CMS, and intrastate agencies and entities based on MITA Framework and industry standards. Access to information takes 24 hours or less.
  4. LEVEL 4SMA obtains information easily and exchanges with state, district, and federal law enforcement, CMS, and interstate agencies and entities. Accessibility is greater than Level 3.
  5. LEVEL 5SMA obtains information easily and exchanges with state, district, and federal law enforcement, CMS, and other federal agencies and entities. Accessibility is greater than Level 4.

Business Capability Quality: Cost Effectiveness

What is the cost of the process compared to the benefits of its results?
  1. LEVEL 1High relative cost due to low number of automatic, standardized tasks.
  2. LEVEL 2Automation improves process and allows focus on exception resolution, improving cost effectiveness ratio over Level 1.
  3. LEVEL 3SMA adopts MITA Framework, industry standards, state and federal law enforcement, CMS, and other nationally recognized standards further improving cost effectiveness ratio over Level 2.
  4. LEVEL 4SMA adopts MITA Framework, industry standards, state, district, and federal law enforcement, CMS, and other nationally recognized standards for interstate information exchange. SMA increases cost effectiveness ratio over Level 3.
  5. LEVEL 5SMA adopts MITA Framework, industry standards, state, district, and federal law enforcement, CMS, other federal agencies, and other nationally recognized standards for national (and international) information exchange. SMA increases cost effectiveness ratio over level 4.

Business Capability Quality: Effort to Perform; Efficiency

How efficient is the process?
  1. LEVEL 1Process is labor intensive. There is wasted effort or expense to accomplish tasks. Process meets minimum state process guidelines and SMA performance standards. Efficiency is low.
  2. LEVEL 2Automation and state standards increase productivity. Efficiency is higher than Level 1.
  3. LEVEL 3SMA adopts MITA Framework, industry standards and information exchange with state and federal law enforcement, CMS, and intrastate agencies and entities improving efficiency to 95% or higher.
  4. LEVEL 4SMA adopts MITA Framework, industry standards and information exchange with state, district, and federal law enforcement, CMS, and interstate agencies and entities improving efficiency to 98% or higher.
  5. LEVEL 5SMA adopts MITA Framework, industry standards and information exchange with state, district, and federal law enforcement, CMS, and other federal agencies and entities improving efficiency to 98% or higher.

Business Capability Quality: Accuracy of Process Results

How accurate are the results of the process?
  1. LEVEL 1Manual processes result in greater opportunity for human error. Accuracy is low.
  2. LEVEL 2Automation and standardized business rules definitions reduce error and improve accuracy above Level 1.
  3. LEVEL 3SMA adopts MITA Framework, industry standards and information exchange with state and federal law enforcement, CMS, and intrastate agencies and entities improving accuracy to 98% or higher.
  4. LEVEL 4SMA adopts MITA Framework, industry standards and information exchange with state, district, and federal law enforcement, CMS, and interstate agencies and entities improving accuracy to 98% or higher.
  5. LEVEL 5SMA adopts MITA Framework, industry standards and information exchange with state, district, and federal law enforcement, CMS, and other federal agencies and entities improving accuracy to 98% or higher.

Business Capability Quality: Utility or Value to Stakeholders

Does the business process satisfy stakeholders?
  1. LEVEL 1Stakeholders lack confidence in information negatively affecting stakeholder satisfaction with the process.
  2. LEVEL 2Automation and standardization provides clear and useful information. Stakeholder satisfaction is greater than Level 1.
  3. LEVEL 3SMA adopts MITA Framework, industry standards and information exchange with state and federal law enforcement, CMS, and intrastate agencies and entities improving stakeholder satisfaction to 90% or higher. SMA uses survey or questionnaire for information collection.
  4. LEVEL 4SMA adopts MITA Framework, industry standards and information exchange with state, district, and federal law enforcement, CMS, and interstate agencies and entities improving stakeholder satisfaction to 95% or higher.
  5. LEVEL 5SMA adopts MITA Framework, industry standards and information exchange with state, district, and federal law enforcement, CMS, and other federal agencies and entities improving stakeholder satisfaction to 98% or higher.

Source: CMS MITA 3.0 Business Capability Model, Performance Management BCM.pdf, pages 21-29.

Other Performance Management processes