When Prior Auth Parity Is Only Verifiable on Paper
Two HHS Office of Inspector General audits released in August examined prior authorization parity across six Medicaid managed care organizations in New York and Kansas. All six MCOs had prior authorization practices that complied with mental health and substance use disorder parity requirements as written. But when OIG examined how those requirements operated in practice, it found denial-rate disparities the states had not identified, required analyses that had not been requested or reviewed, and supporting data that could not always be reproduced.
The Written Policies Met Parity Requirements
Federal parity requirements prohibit Medicaid MCOs from applying prior authorization limitations to mental health and substance use disorder benefits more stringently than they apply them to medical and surgical benefits in the same benefit classification. OIG examined those limitations both as written, through the MCOs’ policies and procedures, and in operation, through how those policies were applied in practice.
The written findings were consistent across both audits. All three selected New York MCOs’ prior authorization practices complied with parity requirements as written. OIG reached the same conclusion for all three Kansas MCOs. Across six MCOs in two states, OIG did not identify a prior authorization parity failure in the written policies it reviewed.
The Denial Rates the States Had Not Identified
For one New York MCO, OIG was able to examine reliable supporting data for the final three quarters of 2023. Among outpatient out-of-network services requiring prior authorization, mental health denial rates were 69.8%, 69.9%, and 72.7%. Medical and surgical denial rates in the same classification were 24.9%, 28.9%, and 30.0%. New York was unaware of the substantially higher mental health denial rates because it had not requested and reviewed the MCO’s 2023 comparative analysis or the supporting claims information.
OIG found another disparity in Kansas. One MCO denied 34% of prior authorization requests for mental health and substance use disorder outpatient out-of-network services, compared with 22% of medical and surgical requests in the same classification. Kansas had not identified the difference through its monitoring. OIG found that the state became aware of it when auditors brought the issue to its attention.
Higher denial rates do not by themselves establish a parity violation. OIG explicitly described them as potential indicators of noncompliance. Determining whether they reflected a parity problem required examining whether prior authorization criteria were applied comparably and no more stringently to mental health and substance use disorder services. In both states, the denial-rate signal requiring that examination was identified by OIG rather than through the state oversight responsible for monitoring parity compliance.
The Data Could Not Be Fully Reproduced
That examination encountered another problem in New York. All three selected MCOs lacked documentation supporting their comparative analyses for the audit period, and the data they provided did not reconcile to the denial counts reported in those analyses. The MCOs told OIG they had not maintained all of the data used to create the analyses. New York had not obtained the supporting data itself and instead relied on MCO attestations that their analyses were accurate and reliable.
Kansas had not received a complete parity analysis covering the entire 2023 audit period from any of its three MCOs. The state had not requested one despite contractual provisions requiring annual submission. At OIG’s request, the three MCOs performed and provided analyses for the audit period.
One Kansas MCO initially produced an analysis that was incomplete and could not be reconciled to its supporting data. Several subsequent submissions also contained inconsistencies. It took 18 months after OIG’s initial request for the MCO to provide an analysis adequately supported by complete and reconcilable data. Even then, only three of the four required benefit classifications were adequately supported. The finding illustrates why regulatory audits add a separate layer of visibility beyond what organizations report about their own processes.
The Oversight Failures Went Beyond the Data
Kansas had contractual provisions requiring its MCOs to demonstrate parity compliance, yet the state did not enforce the requirement that they conduct annual parity analyses. OIG also found that Kansas had not provided detailed instructions explaining how to conduct those analyses or what supporting documentation should be provided. Through the end of OIG’s fieldwork in February 2026, responsibility for parity oversight between the Kansas Department of Health and Environment and the Kansas Department for Aging and Disability Services had remained unassigned.
New York had a considerably more developed oversight structure. Its compliance program included comparative analyses, annual certifications, denial monitoring, corrective action plans, technical guidance, and a 20% denial-rate threshold. Yet the state did not obtain the data supporting the MCOs’ comparative analyses and did not always promptly follow up when mental health and substance use disorder denial rates exceeded its threshold. During the state’s most recent reviews, two of the three selected MCOs continued to be noncompliant with prior authorization parity requirements more than six years after the October 2017 compliance deadline.
The written policies were the clearest part of the compliance picture across both audits. Every MCO OIG reviewed met prior authorization parity requirements as written. Establishing how those policies operated required the analyses to be completed, the underlying data to be retained, the states to obtain and review them, and the results to be examined when they indicated potential problems.
OIG found breakdowns at each of those points. Some analyses had not been requested. Some supporting data could no longer be reproduced. Denial-rate disparities had gone unidentified. In Kansas, federal auditors had to request analyses the state itself had not required its MCOs to produce for the audit period. The gap resembles a broader problem in public prior authorization transparency: having a required disclosure or compliance artifact does not necessarily mean the information needed to interpret what happened underneath it is available.
The policies established how prior authorization was supposed to operate. It took OIG asking for the records underneath them to expose how much the existing oversight could not establish about whether it actually did.
The Prior Auth Report provides monthly analysis of published payer data, prior authorization policy, and the administrative patterns shaping utilization management.
If you'd like structured analysis delivered directly to your inbox, you can subscribe to the newsletter below.