Government Technology Review
CIO StrategyLong read

Healthcare Data Governance Framework Requirements for State Medicaid Agencies

States must align HIPAA, T-MSIS, and interoperability rules into one governed data framework.

Correspondent · · 11 min read
Cover illustration for “Healthcare Data Governance Framework Requirements for State Medicaid Agencies”
CIO Strategy · September 13, 2026 · 11 min read · 2,476 words

Medicaid oversight isn't a bunch of different compliance jobs anymore. One role in many disguises, and states treating the work as scattered efforts are the ones flunking audits they ought to have cleared. HIPAA, HITECH, T-MSIS, modular certification, interoperability mandates, quality stratification, payment transparency, program integrity, plus a new legislative mandate now. 1, each points to one underlying need: clear, well-governed, traceable data. When a state builds a fresh compliance process around every requirement, it repeats identical tasks repeatedly and poorly, yet most states treat this as an unavoidable expense instead of recognizing their own mistake.

This begins with the Social Security Act’s Section 1903(r). It requires states to keep mechanized payment and information retrieval technology that works, fits Medicare's setup, and follows any rules the Secretary names. It is the plain statutory floor, never just suggestion, sitting beneath all MMIS work for years. HIPAA sits above that foundation, laying out how health information must stay secure through confidentiality, integrity, and access controls across any system reviewing eligibility, billing, and provider data for huge populations. HITECH later extended these obligations to contractors and reinforced electronic PHI safeguards, which matters because nearly all MMIS data now resides in electronic form. A state running modernization must fold HITECH's electronic PHI rules into its architecture right away, rather than adding them once go-live happens.

No state should view this as a past issue. These obligations are shaping architecture decisions now since MMIS keeps so much health and personal data, leaving it exposed to breaches and recurring government scrutiny. T-MSIS, modular certification, interoperability, and quality reporting all sit on that base. Without that, nothing else works.

T-MSIS: the national reporting backbone and what CMS now enforces against states that fall short

T-MSIS (Transformed Medicaid Statistical Information System) is CMS's drive toward one trusted, full account of Medicaid and CHIP data, covering oversight, public health analysis, and program decision-making. States send beneficiary demographics and eligibility data to it, plus records for inpatient, long-term care, services, prescriptions, money flows, provider details, information on managed care, and data on third-party coverage. It sits on infrastructure that CMS builds by pairing agile with DevSecOps methods, in line with the Digital Services Playbook.

Now they actually follow through. In September 2025, CMS resumed its Data Quality compliance reviews and later reinstated the routine MES Approval Processes. When a state's data falls short following two consecutive months of review, CMS initiates the Reapproval and MES Compliance Process by sending notice that requires a corrective action plan in 30 days. The deadline comes with something at stake.

Data quality is no longer just a dashboard metric. The bar is now externally audited and federally enforced, with remediation deadlines attached, and any state handling T-MSIS reporting as a casual routine instead of the governed process will be first in line for that notice. Don't act shocked when you get it.

MMIS modernization requirements: modular certification, MITA, and FHIR compliance

During 2022, CMS scrapped the all-at-once certification process in favor of Streamlined Modular Certification, or SMC, under which it evaluates system modules one by one rather than making each state's whole MMIS clear at once. CMS folded Electronic Visit Verification into the existing SMC certification framework in 2025. Underneath it all, States must maintain compliance with MITA, HIPAA, MECT, and FHIR standards, while their modernization architecture needs to anticipate future requirements rather than only current ones.

SMC came about because states clinging to that model chase a strategy that already lost once, and swapping everything at once won't work anymore. Many state platforms used COBOL, including some from 1970s builds, with online front-ends bolted onto them during 1990s work to seem modern. Programmers able to service that software grow fewer each year, and full-system overhauls by states often proved challenging and costly. Putting certification in modules answers that failed path: change one part, certify that part, then keep going.

On the governance side, compliance gets tracked module by module rather than system-wide. Any state might stay mid-remediation for adjudication even with eligibility determination certified. A governance framework that only reports "certified" or "not certified" at the system level will miss exactly the granularity CMS now expects, and that gap is where states get caught flat.

Interoperability mandates: TEFCA participation and the 2027 API deadline

CMS final rule 89 FR 8758, issued February 8, 2024, requires Medicaid Managed Care Plans and State Medicaid Agencies to stand up APIs supporting electronic prior authorization, with a 2027 deadline attached. As more agencies sign on to Trusted Exchange Framework plus Common Agreement (TEFCA), states need new governance covering data sharing across agencies. The agencies moving toward that framework are Social Security Administration, Department of Veterans Affairs, Defense Department, CDC, CMS, NIH, and Indian Health Service. Those groups quickly produce practical use cases: eligibility determination drawing on several government records, plus care coordination helping beneficiaries who are dually covered under Medicare alongside Medicaid, along with public health reporting shared across departments.

Interoperability is no longer optional or bilateral. Every state's governance framework must define who may access which data, and when, as more national agencies join the system. All of it depends on what prior parts already demand: APIs with FHIR compliance, plus standardized data underneath reaching a benchmark of reporting-grade quality. These requirements build on one another rather than fitting neatly side by side, each leaning on what came before.

Quality reporting obligations and the stratification requirements taking effect for FFY 2026

Under 42 CFR § 438.340, states must review and better the managed care services they offer, pick measurable targets, and create their own adequacy standards for providers. In 2024, the Managed, Care, Access, Finance and Quality Final Rule, CMS 2439-F, went further by clarifying public input requirements, making states share findings from three-year quality strategy checks on pages that are public-facing, and requiring states to share findings from three-year quality strategy checks on public-facing pages.

FFY 2026 brings the sharper requirement. Under SMD 25-002, issued on July 11, 2025, states holding Health Home State Plan Amendments are to file stratified data for 50% of the required Core Set into the Quality Measure Reporting system no later than December 31, 2026. Stratification must report race and ethnicity, sex, and geography separately. For 2026, the section 1945 Health Home topics are Colorectal Cancer Screening, Follow-Up once Hospitalized for Mental Illness, Controlling High Blood Pressure, Follow-Up after an Emergency Department Visit involving Substance Use, Follow-Up after an Emergency Department Visit tied to Mental Illness, and Pharmacotherapy Use to treat Opioid Use Disorder.

Upstream data decisions now face their reckoning, and no shortcut exists. Stratified reporting depends on underlying data gathered at sufficient granularity from day one: ethnicity, sex, and geography recorded accurately at intake, rather than reconstructed later. Retrofitting disaggregation across old data costs too much, takes too long, while still being error-prone, as a state putting this off to 2026 has already missed its window. Governance frameworks must set standards upstream, long ahead of that deadline, or else December 2026 is a scramble everyone loses.

Payment rate transparency and the July 1, 2026 FFS disclosure deadline

Issued on 10 May 2024, the CMS final rule CMS-2442-F requires states to disclose fee-for-service payment amounts, and compliance must happen before 1 July 2026. It may seem to be reporting work, but what’s underlying goes further: payment rate data must be correct, formatted the same way, plus auditable when needed, not merely retrievable.

This rule affects key aspects of state operations, including: payment rate transparency, comparative rate studies, restructuring or cutting rates, setting up panels, and checking direct-care staff pay. Every one of these needs data that stays aligned and gets cross-referenced against quality and encounter records, rather than managed inside its own silo. If a state walls its payment records off from quality reporting, the disclosures it files won't stand up to scrutiny. If you chase a shortcut just when it's easy, it was never worth chasing. The requirement is a matter of compliance.

Program integrity oversight and the high-risk areas CMS is auditing through 2028

Under the Social Security Act, Section 1936(d) directs HHS to draft a comprehensive integrity plan every recurring five-year cycle. The Comprehensive Medicaid Integrity Plan covering FY 2024 to 2028 organizes its efforts into four main areas. Managed Care Oversight covers service utilization analytics, certification audits on rates, checks of plan agreements, plus Unified Program Integrity Contractors oversight. Determination audits for eligibility, corrective action plans linked to Payment Error Rate Measurement, plus the Medicaid Eligibility Quality Control Program, all fall under Access and Care within Program Sustainability. High-Risk Vulnerabilities covers assessments across managed care, Non-Emergency Medical Transportation, oral health, skilled nursing, plus Home and Community-Based Services. The plan also includes data-sharing initiatives, collaboration, education, and technical assistance.

Because Medicaid is so big and complicated, GAO's high-risk roster has included the program since 2003, showing how tough it is to oversee nationally. States must therefore ensure robust oversight from the outset. Stauffer and Myers say state program integrity teams face high-urgency work as 2026 starts: finding managed care theft, loss, and cheating, plus oversight of high-risk service areas.

With this risk-based setup, Audit-readiness should not turn into once-a-year chaos. State program integrity teams most often make the mistake of Treating it that way. Data must remain traceable and continuously ready, since an audit might hit those service settings with little notice.

H.R. 1 and the new eligibility and financing obligations states must now build into their data infrastructure

With H.R. 1, a reconciliation bill passed July 4, 2025, states face a new set of data and program demands beyond what already exists. Because of the new requirements, states must build verification tools to see if beneficiaries satisfy the eligibility rules, do system readiness assessments showing their infrastructure handles those tasks, and use actuarial modeling for gauging costs. Each one needs eligibility data in structured form, not kept scattered through old records no one has used in years.

State-Directed Payments and Provider fees add their own burden. Alongside CMS's provider tax loophole rule (CMS-2452-P), H.R. 1 requires states to check if existing provider tax plans meet new standards, analyze cost effects, and watch the ways Managed Care Final Rule keeps shifting underneath them, which generates another reporting layer and added documentation.

Then there's the Rural Health Transformation Program, established under Section 71401: a $50 billion federal initiative distributing $10 billion in total annual allotments across states from 2026 through 2030. All 50 states applied, and award decisions came down December 29, 2025. Putting it in place now demands tight program oversight, with data frameworks made to follow the funds and the results expected.

In effect, H.R. 1 acts like a stress test. When eligibility, financing, and reporting requirements all hit together, any state running fragmented data will watch them collide instead of coming one by one. This collision is exactly what a stress test does: it reveals which seam gives.

Why AI governance is becoming an additional compliance layer, not a separate initiative

In December 2025, HHS put out a strategy to handle risk, grow the workforce, cut red tape, and keep running track of how AI use cases fit wider government requirements. CMS considers AI foundational to oversight, administration, as well as care services, and by April 2026 had put out the opening round of the Health Technology Ecosystem suite, with over 700 groups pledging backing and products from more than 50 firms in use or being built.

Under the CMS Prior Authorization Final Rule, payers must tighten AI timeframes and maintain audit-ready data for those choices. After the rule went into effect, no payer could treat Prior authorization automation as something handled internally. The workflow is federally regulated now, and documentation obligations attach to each call the algorithm makes.

On their own, States are acting quickly too. Over 280 healthcare AI bills were introduced in 2026, covering transparency and disclosure requirements, AI chatbot use, and utilization management, and roughly half the states had adopted NAIC AI governance guidance by early-to-mid 2026. More states now spanning jurisdictions nationwide, with rules in force between 2024 and 2028 and one more state still deciding, require a provider to own or issue every denial on medical-necessity grounds, although AI may help with the decision. Programs used to diagnose, forecast, or suggest care for one person might face oversight from the FDA, classified as a Medical Device under Software rules, and need premarket checks via 510(k) or De Novo or PMA filings.

All of it sits within data governance. States treating compliance as a standalone workstream guarantee two losses, a mistake worth noting. They create one AI group, a different audit process, plus another documentation set with standards, acting like those data underneath are not that same data, governed already (or not), by the rules above. Audit trails, inventories, discrimination write-ups, and override notes are, at root, all data. Any state missing real governance framework rules already falls short on T-MSIS and program integrity obligations, so AI compliance won't go any easier.

What a coherent data governance framework actually provides across all these layers

Look at the whole picture and it's clear. T-MSIS, SMC, HIPAA, HITECH, interoperability-mandate-driven APIs, quality stratification, transparency in FFS rate, plus CMIP program integrity plan work, and one new legislative mandate. 1's eligibility and financing shifts, plus today's AI oversight, each push their own data needs. Tackle each separately, on its own, and any state gets stuck with redundant effort, inconsistent data between programs, and gaps some auditor catches the moment an audit starts. Most states default to this trap, since treating any given mandate like a separate job feels simpler in the short-term but costs more long-term.

A governance framework that works fixes this by anchoring each layer onto one shared underlying base. Since reporting platforms share the same Data standards plus definitions, one beneficiary file will satisfy T-MSIS requirements, drive quality measure stratification work, and handle eligibility verification checks without being transformed or corrupted. Stewardship and responsibility get handed out in plain language, so data quality accountability sits with whoever holds the data at the origin, not whoever ends up pressing send on the file. Access rules satisfy HIPAA's minimum-necessary requirement yet still permit the exchange that coordination across agencies and TEFCA require. Audit trails stay current continuously, instead of getting reconstructed amid pressure when CMIP scrutiny or AI documentation demands arrive. With a clear process for handling updates, a state can absorb any fresh CMS quality measure or additional legislative mandate. 1-style reconciliation bill, without ripping up the underlying architecture to fit it.

The SMC comparison deserves some thought. Like modular certification, which evaluates a single system part and keeps it accountable, layered governance in a framework likewise assigns standards, with accountability across each part. Each one backs the other: modular work calls for modular governance, while that same modular governance keeps modular certification survivable as it grows.

Filed underCIO Strategy

More in CIO Strategy