States can modernize Medicaid systems faster than they think
TL;DR
- Medicaid modernization can happen incrementally. You don't need a five-year overhaul.
- Legacy systems and shrinking technical talent are increasing cost, risk, and response times.
- State-owned data and architecture can reduce vendor lock-in and increase control.
- Real-time analytics can help prevent improper payments and strengthen program oversight.
- Start with today’s mandate and use each requirement to progressively modernize.
Old assumptions about Medicaid modernization are changing
State Medicaid and eligibility agencies have until January 1, 2027, to meet new eligibility requirements under H.R. 1, which became law in July 2025.
What does that mean for you?
Renewals go up, verification gets harder, and some of what you need to verify lives outside your system. With just four months to meet requirements, that’s not much time to prepare for a change this size, especially since most agencies will be making it in eligibility systems that are 40 years old.
Why are agencies still in a holding pattern? Three beliefs hold agencies back from updating their legacy infrastructure:
- Modernization projects take five years and a nine-figure budget.
- A vendor ends up owning whatever gets built.
- Improper payments are a normal cost of running the program.
All three used to be true. Today, none of them are.
But the cost of acting as if they were keeps going up.
You have less time than you used to
Federal and state requirements keep coming while the window to meet them keeps shrinking. A major program change once took two or three years to complete. Now, the expectation is months.
Most legacy platforms can’t move that fast. They aren’t modular, so changing one piece of core code means redoing and retesting everything around it. A single new regulation can take six months to build in a legacy system and three more months to test internally before user acceptance testing ever begins.
In the end, meeting one mandate doesn’t just take a year. It takes your whole year. Your backlog doesn’t budge, improvements your team wants to build never ship, and every available hour goes to meeting requirements instead of making any enhancements to help the program.
Technology debt is becoming workforce debt
Systems are only half the problem. The other half is that almost everyone who knows how to work on them is gone.
Take a programming language like IDEAL, which hasn’t been taught anywhere in about 30 years. This lack of instruction limits your hiring pool to people decades into their careers, and it shrinks with each retirement. You can’t outsource your way out of this problem.
Agencies get a full-throated “No” when they ask the vendors who own the underlying mainframe patents to take these systems on. Why? Those vendors don’t have the expertise in these old coding languages either.
That deficit leaves you with a staffing model you can’t maintain. Every developer must be senior level, because nobody is teaching this skill to new talent. The results? No entry-level roles, no career path, and no succession plan.
Newer technology changes that. You can hire an entry-level engineer, build their experience, and offer a clear career path. Modernizing is also how you rebuild a hiring pipeline. As more people retire, it may be the only one available to you.
Modernization happens in phases now
So why haven’t organizations abandoned legacy systems? It isn’t for lack of recognizing the problem. What stops them is their picture of the solution.
Leaders still imagine the version from 40 years ago, when a mainframe cost roughly $100 million before you built a single thing on it. Using that model, replacing a system means a budget request in the hundreds of millions, a multiyear timeline, and every staff member you have working on it.
You also get nothing until the very end. Your team builds the whole system before any of it goes live. An agency can spend four years and a fortune and have no working software to show for it. Plenty of these projects never get turned on, because they were never “ready.”
Cloud and software as a service (SaaS) brought the entry cost down far enough to change what modernization projects look like. Instead of replacing your entire system, you can now take your next mandate requirement and build outside that system.
Build that piece on a modern platform, then build the next one there too. After you do that a few times, you’ll discover you’ve replaced a real share of the old system while still completing your daily work.
This is where modernization pays off. If a change that tied up your development team for a year now takes months, you just gave that team back most of a year. Do it again, and you’re no longer playing catch-up.
You can own the platform, the data, and the roadmap
Working in phases only adds up if each phase builds on the last. That process requires decisions vendors cannot make for you.
Start with a roadmap:
- It should be a living document, and it doesn’t have to be exhaustive.
- Some states run detailed 100-page plans; others work from five pages.
- It should name your platform choices, including which cloud, which database, and which front-end layer you use.
Without those choices, vendors make them for you one procurement at a time, so you end up running eight different clouds that nobody on your team can work across. Instead, decide once, then have every engineer work on the same stack.
Next, you need to own the environment itself. 15 years ago, it made sense to require bidders to bring their own infrastructure. That’s no longer true, but the contracting model hasn’t caught up. Cloud costs get passed through to you anyway, so it’s a no-brainer to own your cloud subscription and allow vendors to build inside it.
You’ll see the difference when a contract ends:
- If you own the environment, swapping vendors is as simple as turning off someone’s access.
- If you don’t own it, you’re migrating data, rebuilding workflows, and receiving a change order for a new ingestion pipeline that can run well into seven figures.
Plenty of states see that big number and decide it’s cheaper to stay. That’s how you end up locked in with one vendor without ever agreeing to it.
Fraud moves in real time, but batch processing doesn’t
A real-time environment also enables you to check a claim before you pay it, instead of finding out months later you shouldn’t have.
That costs real money. Medicaid’s national improper payment rate rose to 6.12% in 2025, up from 5.09% the year before. How much of that is exactly fraud, waste, and abuse isn’t known, but it runs into the billions, and the people attacking these programs have modern technology while your systems don’t.
The reason is timing. Older platforms run in batches, so work stacks up and processes overnight or weekly, meaning checks happen after payment, not before.
Slowing down to investigate isn’t an option. Providers may have 6–12 months to submit a claim, but once it arrives, states usually have 15–30 days to pay it. There's no room for a manual review, so states pay fast and check later (an approach the industry calls “pay and chase”).
- When the provider is honest, that works.
- When it’s organized fraud, the money is long gone before anyone runs a report.
Checking earlier isn’t the same as checking harder, either. Nearly every Medicaid program runs pre-adjudication claim edits, but those are fixed rules that only catch what someone thought to write down in advance.
Real-time detection scores each claim as it arrives and pushes suspicious ones to the front of the line. Behavioral analytics go further, learning what normal looks like for a given provider and flagging what doesn’t fit. A provider who enrolled last week, and is already billing at volume, hasn’t broken a rule. But that pattern isn't normal.
Your oversight is only as good as your visibility
Medicaid managed care—which covers about three-quarters of Medicaid beneficiaries—can present a similar problem in a different form. The number that’s supposed to tell you whether payments are going out correctly isn’t measuring the part where things can go wrong in the system.
The federal improper payment estimate for managed care has recently come in at or near zero. That number measures something narrower than it sounds. It checks whether states paid their plans the right amount. What happens next, when plans pay providers, falls outside it. The Government Accountability Office, the Department of Health and Human Services Office of Inspector General, and state auditors have all flagged risks the estimate never touches, including plans paying for services that weren’t delivered.
That leaves the job to you.
Managed care contracts have service-level agreements on network adequacy, screening rates, and access, but few specify how plans must submit any of it. Those submissions can show up as spreadsheets, encounter files, and the occasional assurance that it got done. Someone on staff compiles it all by hand in a workbook that’s been growing for a decade, got handed off when the last person retired, and now breaks in ways nobody can trace. A problem surfaces three weeks later, by which point next month’s files are already in the inbox. And nobody at a managed care organization is going to flag a target their plan missed.
If you give that same work to a system with a required intake format and built-in pass-fail scoring, three weeks of compiling becomes minutes. AI can go further and tell you why each one failed. Now, you’re having the conversation in hours instead of months. A plan running low on diabetes prescreenings, when caught early, means someone gets treated before they’re diagnosed. That’s a better result for that person and at a fraction of what it costs the program to manage the disease later.
Keep that in mind as you plan. AI like that belongs across nearly every back-office function in health and human services. Direct contact with members is the exception. When someone needs dialysis today, they need to reach a person. These agencies serve the most vulnerable people in the state.
Modernization should give your staff more time for them, not put more technology in the way.
Where to start modernizing Medicaid systems
Five moves are worth making to get your systems back under your control and ready for modernization. Here’s what we’d advise a state that’s ready to go:
- Build a state-owned data foundation. Put your Medicaid Management Information System, eligibility, providers, encounters, plans, and program integrity into one governed data layer so that you can make decisions with the whole picture in view.
- Shift from recovery to prevention. Prepayment analytics, risk scoring, and targeted review stop improper payments before money leaves the program.
- Reduce your reliance on legacy systems and the shrinking workforce that runs them. Modernize mainframes and tightly coupled applications one mandate at a time, so you build capacity ahead of the next requirement instead of scrambling to meet it.
- Strengthen managed care oversight. Ask for independent visibility into encounter quality, plan performance, provider activity, and the fraud patterns nobody will report to you.
- Keep the architecture yours. Choose modular, interoperable systems so your data, your roadmap, and your next move stay under your control.
The best time to start a modernization was a year ago. The second-best time is now, and every month you wait adds risk without buying you anything. Take the mandate in front of you, build it somewhere modern, then let the next one grow from there.