PAN Lab example
Medicaid unwinding ex-parte renewals
The unit of determination: an automated renewal system at population scale
In 2023, 30 states' Medicaid renewal systems judged eligibility per household, not per person. States improperly ended coverage for nearly 500,000 people, many children.
See more
Ex parte renewal is the automated step that state Medicaid agencies run to renew coverage without asking the enrollee for anything. It matches the enrollee's records against wage, tax, SNAP food assistance, unemployment, and Social Security data. In 30 states, it evaluated renewals by household instead of by person, the unit federal rules require.
How it is used
A pandemic-era protection kept people enrolled in Medicaid from March 2020. It ended on 31 March 2023. States then had to redetermine eligibility for their entire Medicaid and CHIP population over a roughly year-long unwinding. CHIP is the Children's Health Insurance Program.
Federal rules require states to try ex parte renewal first, before asking for a paper form. Done correctly, it protects enrollees, because it renews them without any paperwork.
KFF, a health policy research organization, reported that about 55 percent of retained coverage was renewed ex parte as of October 2023. That rose to 61 percent of renewals by September 2024. States ranged from about 99 percent in North Carolina to about 3 percent in Wyoming.
What went wrong
On 30 August 2023, the Centers for Medicare & Medicaid Services (CMS), the federal agency over Medicaid, notified states of a defect. Their systems ran ex parte renewals at the household or family level. Federal rules require the individual level.
This setting is called the unit of determination. When any one household member could not be renewed automatically, the whole household was sent a form. If the state did not get the form back, it ended coverage for everyone in the household on procedural grounds. That means over paperwork, not a finding that anyone was ineligible. The sources do not say why forms were not returned.
The case file says the system was accurate in the ordinary sense. It did exactly what it was configured to do. The error was in the specification, so no accuracy measure would have surfaced it.
Who was harmed
Children were hit hardest. Their income limits for eligibility are far higher than adults', so a child often stayed eligible when a parent did not.
The Office of the Assistant Secretary for Planning and Evaluation (ASPE), in the federal health department, projected that about 74 percent of disenrolled children would still be eligible. That is a projection, not an audit afterward.
How it was caught
CMS found the defect in 30 states. It ordered them to pause procedural disenrollments, reinstate coverage, adopt mitigation CMS approved, and reprogram to person-by-person renewal.
On 21 September 2023, CMS announced that nearly 500,000 children and other people would regain coverage. That figure adds up estimates the states reported to CMS. It is not an independently audited count.
The case file calls one move the most effective: a halt authorized in advance. CMS ordered states to pause procedural disenrollments for affected people.
Who decides
The states run the renewal systems and reprogrammed them. CMS oversees them. Section 5131 of the Consolidated Appropriations Act, 2023 gave CMS mandatory monthly state reporting and the power to order procedural disenrollments paused.
For states that did not comply, it added a cut to federal Medicaid funding, civil monetary penalties, and corrective action plans. An interim final rule of 6 December 2023 put these powers into regulation.
What the oversight did and did not do
The federal loop worked. Its monthly reporting and its power to pause terminations caught the defect and forced reinstatement across 30 states within months.
But it caught the defect after mass terminations, not before. Its check ran on totals the states reported each month, not on each decision when it was made.
The case file contrasts this with Michigan's MiDAS, which issued tens of thousands of false fraud findings. It also contrasts Australia's Robodebt, which raised hundreds of thousands of debts by an unlawful averaging method. There, corrections came years later from courts and a Royal Commission.
The wider unwinding
The defect was one part of a much larger loss of coverage. KFF recorded about 25.2 million people disenrolled as of 12 September 2024. Of those disenrollments, 69 percent were for procedural reasons.
The Government Accountability Office (GAO) found about 27 million disenrolled in the first 18 months. The two totals cover different periods and use different methods, so they do not conflict.
Some states failed the opposite way. They used ex parte renewal too little, which shifted the work onto paper forms and state processing backlogs, both prone to error.
What this case asks
The case file says the useful governance moves here are not accuracy fixes. The first is an independent person-by-person check of the household-level result.
The second is a check of each termination against the person's own eligibility before disenrollment. The third is a faster review rhythm, so a population-scale mistake is caught while terminations are still happening.
The case file also credits the monthly reports, with their counts and reasons for disenrollment, as the honest data that made the catch possible.
What the available tools can and cannot address
A failure pathway is a link between two parts of the network where a mistake made by one part can be passed on to the other. A pathway counts as closed once it passes on only a few mistakes. It need not stop them all.
This case's budget is 12 units. Each tool costs units from it.
Explore (No Targets) sets no targets. Under Service Targets Only, the targets can be met. The cheapest way is one tool, Vet connections, costing 3 units.
Vet connections lets one system retrieve or copy another's records only where that is explicitly granted. On this network, mistakes stop passing along three pathways. They are Cross-agency data matched for renewal, Prior enrollment records reused in matching, and Termination applied to coverage and managed care. It also limits how readily one mistake repeats along the pathway named One rule set for every renewal.
The first of those is the data match federal rules require. Closing it means mistakes stop passing along it, not that the match stops.
Under Service and Safety Targets, the targets include closing every failure pathway, and they can be met. The cheapest combination uses Vet connections, Understand the system, and Store less data.
At this level, Understand the system costs 4 and cuts Store less data from 3 to 2. The three cost 9 of the 12 units. Every combination that meets these targets includes all three.
Understand the system funds study of what the deployment is doing, and caseworkers correct more mistakes. Store less data limits what the renewal system and caseworkers write into the coverage record.
None of them uses Check with a second model or Check copied records. Those are the two tools that add the person-by-person checks this case is about.
Under All Governance Targets, this case is not fully addressable with the available tools. That level also asks for a larger, steadier gain in service, meaning the benefit the deployment delivers. Every combination within the budget was checked.
The best one that closes every failure pathway and meets the target on the deployment's environmental footprint falls just short of that service target.
Open this example in PAN Lab v0.1 to apply pressures and levers and watch what the system does.
What this models
This example runs on the Ex-parte-renewal-class automated eligibility system with a federal monitoring loop network: 7 components and 12 pathways between them. Every context in the Lab is a stylized model, never a reconstruction of any actual deployment, and each assumption behind it carries a provenance label.
Evidence base: 7 assumed · 1 published baseline. In the Lab, the shaded evidence band behind each headline readout draws its width from the least-established class below.
Show all 8 assumptions
- assumed
This example follows the pattern the case file documents for the automated renewals of the Medicaid unwinding: one wrong setting repeated at the scale of a whole population. It is not a copy of any state's actual system.
- baseline
The pathway named One rule set for every renewal stands for one set of rules applied the same way to every renewal. So one wrong setting, the unit of determination, repeats across the whole population instead of averaging out. That is why the defect showed up as nearly 500,000 improper disenrollments across 30 states, not as scattered mistakes. Michigan's MiDAS system shows the same pattern: one rule set produced tens of thousands of wrongful fraud findings.
- assumed
This example draws the renewal system as data-matching rules, not as a model that predicts or scores risk. The documented failure was a setting: renewals were evaluated by household instead of by person, the unit federal rules require. So the error lay in the specification, not in the system's accuracy. No accuracy measure would have found it.
- assumed
This example assumes few automated terminations were corrected before they took effect. Caseworkers see only the cases sent to the paper renewal, and they correct the record one case at a time. The sources say that when the state did not get a household's form back, it ended coverage for the whole household on procedural grounds. They do not say why forms were not returned. They say individual override was limited until states reprogrammed their systems and reinstated affected people in large numbers.
- assumed
The Centers for Medicare & Medicaid Services (CMS) is drawn as federal oversight that worked but came late. Its mandatory monthly reporting and its power to order procedural disenrollments paused caught the defect, but only after mass terminations. A check of each termination against the person's own eligibility is drawn too, and the sources describe none. So the gap this case turns on is not missing oversight. It is a person-by-person check at the point each renewal is decided. The case file contrasts this with two other automated systems, Michigan's MiDAS and Australia's Robodebt. There, corrections came years later from courts and a Royal Commission.
- assumed
The household renewal forms are drawn as a part of the network to mark where the defect showed. A whole household was sent a form when any one member could not be renewed automatically. No pathway connects the forms, so they do not change how mistakes move in this example.
- assumed
The cross-agency data match is marked as private. Ex parte renewal matches enrollees' records against wage, tax, Supplemental Nutrition Assistance Program (SNAP), unemployment, and Social Security data. Federal rules require the match, and it protects enrollees when it is set up correctly. So the privacy question here is which sources the match uses, not whether it runs.
- assumed
Harm concentrated on children. Their income limits for eligibility are far higher than adults', so a child often stayed eligible when a parent did not. A uniform household setting therefore hit children hardest. The case file documents that difference. This example shows how errors move among the renewal system, caseworkers, the coverage record, and CMS. It does not model people or groups, and estimates no difference in harm among enrollees.
What this example does not show
Show all 3 limitations
- The figure of nearly 500,000 people improperly disenrolled across 30 states adds up estimates the states reported to the Centers for Medicare & Medicaid Services (CMS). It is not an independently audited count. Totals for all disenrollments differ by source and period. KFF, a health policy research organization, recorded about 25.2 million as of 12 September 2024. The Government Accountability Office (GAO) found about 27 million in the first 18 months. They use different data and methods, so they do not contradict each other.
- Harm concentrated on children, whose higher income limits often kept them eligible when a parent was not. This example does not model people or groups, and estimates no difference in harm among enrollees. The case file documents that concentration. The Office of the Assistant Secretary for Planning and Evaluation (ASPE) projected that about 74 percent of disenrolled children would still be eligible. That is a projection, not an audit afterward.
- The record shows two failures side by side, and this example shows only the first. In 30 states, renewals were evaluated by household. In some states, automated renewal was used too little, which shifted the work onto paper forms and state processing backlogs, both prone to error. Federal rules require automated renewal, and it protects enrollees when set up correctly. This example shows a defect in one setting, not a case against automation.
Sources and evidence
What this example rests on, claim by claim. Every entry resolves to the same ledger the Evidence Registry publishes.
A single automated rule set applied uniformly and without human review produced tens of thousands of correlated wrongful fraud determinations in the documented Michigan MiDAS case — one flaw repeating at caseload scale rather than averaging out.
empirical- Government Michigan AG, settlement of civil-rights class action (Bauserman, 2022) https://www.michigan.gov/ag/news/press-releases/2022/10/20/som-settlement-of-civil-rights-class-action-alleging-false-accusations-of-unemployment-fraud
- Investigative IEEE Spectrum, Michigan's MiDAS unemployment system: Algorithm alchemy that created lead, not gold https://spectrum.ieee.org/michigans-midas-unemployment-system-algorithm-alchemy-that-created-lead-not-gold
Where this connects
Institutional pressures in this domain
- Austerity & recovery incentives — Cost-cutting and overpayment-recovery targets tilt the system toward denial and enforcement errors.
- Vendor opacity — The deploying institution cannot inspect the model, data, or update pipeline it is accountable for.
- Compliance over substance — Paper controls (sign-offs, checklists) satisfy audits while the behavior they describe erodes.
- Reviewer bottleneck — One fixed-capacity checking stage sits between AI output and consequence; everything queues behind it.
All of them in context on the Public benefits & eligibility domain page.
Levers available here and the patterns behind them
- Gate record entries — Human-in-the-loop write gating
- Check with a second model — Cross-model verification
- Check copied records — Reconcile copied records
- Review on schedule — Oversight cadence & retrospectives
- Pause AI on alarms — Deployment circuit-breaker
- Vet connections — Connection authorization
- Understand the system — Understand the system
- Assign a challenger — Structured dissent
- Store less data — Data minimization
- Upgrade model — Improve the model
Documented case histories
- Medicaid unwinding: automated ex parte renewal at population scale
- Michigan MiDAS
- Robodebt (Australia)
- Indiana / IBM eligibility modernization
- Rotterdam welfare-fraud risk model
- Arkansas ARChoices / ARIA
- Netherlands childcare-benefits scandal (Toeslagenaffaire)
- SyRI (Netherlands)
- CNAF benefit-fraud risk score (France)
- Forsakringskassan VAB fraud-selection profile (Sweden)
- Udbetaling Danmark data-driven control (Denmark)
- BOSCO (Spain)
- Serbia Social Card (Socijalna karta)
- UK DWP Universal Credit Advances fraud model
- ID.me identity verification as an unemployment eligibility gate
- INSS auto-analysis: when the productivity metric makes denial the fastest way out
- Samagra Vedika
- Workforce Australia Targeted Compliance Framework: automated payment sanctioning after Robodebt
- NYC MyCity business chatbot
- Nevada DETR generative-AI unemployment appeals
- Tennessee TennCare TEDS