Guides
FDR Oversight for Medicare Advantage Plans: What CMS Requires and How to Automate It
A health plan can push the work down the chain. It cannot push the responsibility. Here is what CMS requires of an FDR oversight program, and which parts a machine can carry.
By HarperAugust 3, 20268 min read
A Medicare Advantage plan delegates claims processing to a TPA. The TPA subcontracts its print and mail to a vendor two states away. That vendor uses a temp agency to staff the mailroom during open enrollment. One of those temps appears on the OIG exclusion list.
CMS holds the plan responsible.
Not the temp agency, not the mail vendor, not the TPA. The plan - which has never heard of any of them, and whose contract with the TPA was signed four years ago by someone who has since left.
That is FDR oversight, and it is the least automatable-looking problem in healthcare compliance. Most of it turns out to be automatable.
The definitions, since they decide the scope
First tier entity. Contracts directly with the MA organization or Part D sponsor to provide administrative services or health care services to enrollees.
Downstream entity. Contracts below the first tier, at any level of the chain, all the way to the pharmacy or the staffing agency at the bottom.
Related entity. Related to the plan by common ownership or control, and either performs some of the plan's management functions under contract or delegation, furnishes services to Medicare enrollees, or leases real property or sells materials to the plan at a cost of more than $2,500 in a contract period.
The word doing the damage in that middle definition is any. There is no depth limit. Your obligation reaches as far as the subcontracting goes, and you find out how far that is only by asking - which is why most plans can name their first tier entities, guess at the downstream ones, and go quiet after that.
The rule everything else hangs from
"Notwithstanding any relationship(s) that the MA organization may have with first tier, downstream, and related entities, the MA organization maintains ultimate responsibility for adhering to and otherwise fully complying with all terms and conditions of its contract with CMS."
That is 42 CFR 422.504(i)(1), current text. We counted every obligation in the CMS contract form it governs, along with six other real healthcare agreements, in our analysis of 540 obligations. Read it as the operating constraint it is: the work can leave the building, the responsibility never does.
The executed CMS contract Alignment Healthcare filed with the SEC in 2021 renders that same provision as "maintains full responsibility" in one article, and as "maintains ultimate responsibility" in another. The regulation has said "ultimate" continuously since at least 2012, so nothing was edited out from under anyone. CMS's own contract form does not match the rule it cites, in a document every Medicare Advantage plan signs. Read your obligations from the CFR, not from the paper in your file.
Everything a good FDR program does is an attempt to close the gap that rule creates between what you are answerable for and what you can see.
What CMS expects
Written agreement from every entity in the chain. 422.504(i)(2) puts the duty on the plan: it must get all first tier, downstream and related entities to agree to the audit, records and preclusion terms. Since the plan has no privity below the first tier, the only practical way to discharge that is a recursive flow-down clause - which is why plan paper reads the way it does. Molina's Cal MediConnect regulatory amendment, drafted against materially identical 422.504(i) language, puts it plainly: the provider "agrees to require all of its first tier, downstream, and related entity(ies) that provide any services benefiting Health Plan's Medicare-Medicaid Program Members to agree in writing to all of the terms provided herein." Your evidence is not that your first tier signed. It is that the whole chain did.
Audit and inspection rights that survive delegation. HHS and the Comptroller General reserve the right to audit the books, contracts, systems and medical records of first tier, downstream and related entities. Your agreements have to preserve that right on their behalf, or you have promised CMS something you cannot deliver.
A 10-year records tail. Inspection rights run 10 years from the final date of the contract period or from the completion of an audit, whichever is later. That clock outlives the relationship, and often the entity.
Exclusion and preclusion screening. 422.504(i)(2)(v) makes every FDR agree that payments will not go to anyone on the CMS preclusion list, and 422.222 and 422.224 put that prohibition directly on the plan. Separately, the OIG updates its exclusion list monthly and its guidance is to screen on hire and monthly thereafter. An annual check leaves months of exposure, and the exposure is not theoretical: payments touching an excluded individual are recoverable.
Training, where your contract still requires it. CMS struck first tier, downstream and related entities from the compliance and FWA training requirement in 42 CFR 422.503(b)(4)(vi)(C), effective contract year 2019. A lot of oversight programs never noticed. What survives is whatever your own delegated agreement obliges - which makes it yours to enforce rather than CMS's to police.
Ongoing monitoring, not an onboarding gate. This is where most programs fail. Diligence at onboarding plus an annual attestation is the shape of nearly every FDR program, and the shape is wrong. Nothing about the risk is annual.
OIG wrote the playbook, in February
For 25 years the only compliance program guidance for this industry was OIG's 1999 document for Medicare+Choice organizations. That changed on 3 February 2026, when HHS's Office of Inspector General published its Industry Segment-Specific Compliance Program Guidance for Medicare Advantage - the MA ICPG. It is voluntary and creates no new legal obligations, which is precisely why it is worth reading: it is the enforcement agency describing what good looks like, without waiting for a rule.
Section II.E is titled Oversight of Third Parties, and its four subsections read like a table of contents for this post: selecting third parties, crafting compliance-focused agreements, ongoing oversight and corrective action, and special considerations for providers.
On agreements, OIG is specific about what to secure in writing - attestations covering the third party's compliance program, "requirements to conduct regular screenings of employees and downstream entities via OIG's LEIE," obligations to report potential violations, and auditing and monitoring rights. It also suggests requiring FDRs to report data at defined intervals, run self-audits and report the results, and standardize credentialing.
And then, on attestations, one sentence that is worth the whole section:
"Attestations may be a way to help mitigate risk, but they should be accompanied by additional compliance-related steps."
That is the enforcement agency saying the annual attestation is a floor, not a program.
Why the annual attestation is the weak point
An attestation is a vendor telling you they did something. It is not evidence that they did.
Consider what changes inside a year without generating a single notification to you: the first tier entity is acquired and its compliance program is folded into the buyer's. A subcontractor is added. A certificate of insurance lapses and renews at lower limits. A downstream entity's exclusion screening quietly stops running when the person who ran it changes jobs. The policy that satisfied a training requirement gets rewritten by someone who never saw the requirement.
Each is invisible to a once-a-year questionnaire, and each is the plan's liability the moment it happens.
The honest description of most FDR programs is that they document oversight rather than perform it. That distinction stays academic right up until an audit, when the question is not whether you asked but whether you knew.
Which parts a machine can carry
Most of FDR oversight is reading and chasing, and both scale badly with people and well with software.
Reading. Every delegated agreement, amendment and flow-down carries the same federal requirement set in slightly different words. Extracted once and stored canonically, that set can be matched against each new agreement instead of re-read - so the two hundredth delegated agreement costs less to process than the first, which is the opposite of how a compliance analyst's time works.
Mapping the chain. Every flow-down clause names the entities it binds. Pulled out of the contract language, those relationships become a graph you can query rather than a diagram somebody drew in 2023.
Chasing evidence. Requesting the signed flow-down, the COI, the training record, the screening result. Following up when it doesn't come. Reading what does come back and checking that it says the right thing - the correct limits, the current dates, the right named entity.
Watching the continuous things. Exclusion and preclusion screening on a real schedule. Certificate expirations before they lapse rather than after - which is harder than a date field makes it look. Retention obligations that persist past termination, because nothing else in your stack will remember them.
Escalating the rest. An ambiguous clause, an entity that has ignored three requests, a discrepancy between what was attested and what the document shows. Those go to a person, with the clause and the evidence attached.
Harper does this work and shows the receipt for each step. Every obligation points back to the clause and CFR cite it came from, every verdict carries the document behind it. When an auditor asks how you concluded a delegated entity was compliant in the third quarter, the trail already exists instead of being reconstructed under time pressure.
What good looks like
A plan running real FDR oversight can answer four questions on any given day, without opening a spreadsheet.
Who is in the chain, to full depth, including the entities your first tier entities brought in.
Which federal requirements flowed down to each of them, in writing, with the executed document.
What is currently unproven - the expired certificate, the screening that hasn't run, the attestation with no evidence behind it.
What changed since last week.
None of that requires a bigger compliance team. It requires that reading and chasing stop being done by people, so the people are free for the calls that carry real judgment - which is the only part of this job that ever needed them.
A one-hour self-audit
Pick your three largest delegated entities and answer these from evidence, not memory:
- Can you produce the signed flow-down for an entity two hops down the chain, or only for your first tier?
- Does anything compare a renewed certificate's limits against what that specific agreement required?
- If a program audit asked how you concluded a given entity was compliant last quarter, would you assemble the answer or retrieve it?
- What remembers the 10-year records obligation on a contract that terminated three years ago?
- Which of your delegated agreements still carry a training obligation, now that CMS no longer requires one?
Question 5 is the one most programs get wrong in both directions - still enforcing what CMS dropped, while missing what their own contracts still require.
Request a Demo
Frequently asked questions
- What is an FDR in Medicare Advantage?
- FDR stands for first tier, downstream, and related entity. A first tier entity enters a written arrangement, acceptable to CMS, with a Medicare Advantage organization or applicant to provide administrative or health care services for a Medicare eligible individual. A downstream entity contracts below that first tier, at any level down the chain to the ultimate provider of services. A related entity is one related to the plan by common ownership or control that performs some of the plan’s management functions under contract or delegation, furnishes services to Medicare enrollees, or leases real property or sells materials to the plan at a cost of more than $2,500 in a contract period.
- What does CMS require for FDR oversight?
- CMS requires that the plan hold ultimate responsibility for its contract regardless of delegation, get every first tier, downstream and related entity to agree in writing to the audit, records and preclusion terms, preserve audit and inspection rights through the chain for 10 years, ensure no payment goes to anyone on the OIG exclusion list or the CMS preclusion list, and monitor delegated performance on an ongoing basis rather than at onboarding only. Note that CMS struck FDRs from the compliance and fraud-waste-abuse training requirement effective contract year 2019 - any training obligation you enforce today is contractual, not regulatory.
- Can a health plan delegate FDR compliance responsibility?
- No. Under 42 CFR 422.504(i)(1), regardless of any relationship the MA organization has with first tier, downstream or related entities, the MA organization maintains ultimate responsibility for complying with all terms of its CMS contract. Delegating a function never delegates the responsibility for it.
- What does the Medicare Advantage ICPG say about FDR oversight?
- The MA ICPG is voluntary compliance program guidance published by HHS OIG on 3 February 2026, the first for this industry since 1999. Section II.E, Oversight of Third Parties, covers selecting third parties, crafting compliance-focused agreements, ongoing oversight and corrective action, and special considerations for providers. On agreements it recommends securing attestations, regular LEIE screening of employees and downstream entities, reporting obligations, and auditing and monitoring rights in writing. On attestations it is blunt: they "may be a way to help mitigate risk, but they should be accompanied by additional compliance-related steps."
- How often should a plan monitor its FDRs?
- Onboarding diligence and an annual attestation are the common floor, and they are not sufficient on their own. The OIG updates its exclusion list monthly and advises screening on hire and monthly thereafter, so an annual check leaves months of exposure. Insurance certificates expire on their own schedule. Subcontractors change mid-term without notice. An oversight program that only checks at onboarding and renewal is blind for the rest of the year.
Sources
- 42 CFR 422.504 - Contract provisions, including 422.504(i) on FDRs (eCFR)
- CMS - Part C and Part D compliance and audits
- HHS Office of Inspector General - Exclusions Program (LEIE)
- SAM.gov - federal exclusions and debarment
- HHS OIG - Industry Segment-Specific Compliance Program Guidance for Medicare Advantage (MA ICPG), 3 February 2026
- 42 CFR 422.2 - Definitions of first tier, downstream and related entity (eCFR)
- 42 CFR 422.503 - Compliance program and training requirements (eCFR)
- 42 CFR 422.224 - Prohibition on payment to excluded and precluded parties (eCFR)
- Molina Healthcare - Cal MediConnect regulatory amendment to group/IPA provider services agreement (EX-10.43, SEC EDGAR)
- HHS OIG - LEIE database and monthly supplement downloads
- CMS - CY2027 Part C Medicare Advantage application (current cycle)
- Alignment Healthcare - CMS contract with eligible Medicare Advantage organization (EX-10.14, SEC EDGAR)