A diverse group of professionals in business attire sit around a conference table reviewing papers and laptops. They’re in a modern office with floor‑to‑ceiling windows that overlook a calm river and city skyline. Warm natural light streams in, highlighting their focused expressions and collaborative posture.

How to Audit Your Mandatory Insurer Reporting Program Before Civil Money Penalties Hit

Mandatory insurer reporting used to be a back‑office chore. You sent files to the Centers for Medicare & Medicaid Services (CMS), cleared any error codes, and moved on. The final rule on Section 111 civil money penalties turns that routine into a board‑level risk issue. Regulations published in December 2023 became effective on October 11, 2024, and enforcement for late reporting started on October 11, 2025. CMS has since clarified that it started random audits in January 2026, with early audits of liability and no‑fault claims expected in February and workers’ compensation audits following in July. A one‑year “compliance clock” still begins for each new settlement or assumption of ongoing responsibility for medicals (ORM), and penalties, now inflation‑adjusted to roughly $1,500 per day per claim, can accumulate up to $365,000 per record. CMS will audit 250 randomly selected records each quarter, so there is no hiding in the crowd.

As a business executive who has spent decades in workers’ compensation, liability, and managed care, I can say the stakes have never been higher. This program affects more than workers’ comp. It touches auto, general liability, self‑insured retentions, captives, and joint powers authorities (JPAs). That breadth means your MIR program is only as strong as its weakest link. The following shares what I’ve learned from being advised by the nation’s top subject matter experts on these issues, who review CMS’s rulemaking and conduct legal analyses. The goal is to help you prepare to audit your program now, before CMS or a plaintiff’s attorney does it for you.

Understand the rule and the timeline

The final rule clarifies that noncompliance is limited to late reporting. CMS abandoned earlier proposals to penalize inaccurate data or high error rates and instead focuses on whether the RRE reported settlements (TPOC events) and assumed ORM within one year of the date they were required to do so. Safe harbors exist for technical errors, CMS system issues, lack of cooperation from a beneficiary, and situations where CMS changes reporting requirements without adequate notice. Recent guidance also spells out a practical good‑faith safe‑harbor procedure for obtaining missing data: If an RRE makes two written requests and one phone or e‑mail attempt to the beneficiary and their attorney, and still cannot get the information, it may avoid penalties for that record.

CMS’s compliance clock begins one year after the later of the settlement/ORM date or October 11, 2024. The agency will send an informal notice if a record is identified as potentially non‑compliant and give the RRE 30 days to provide mitigating evidence; failure to respond triggers a formal notice with appeal rights. Importantly, CMS sends notices to the RRE, not to the reporting agent (in many cases, the TPA), so your team must be ready to respond.

Two more practical updates deserve mention. First, the NGHP User Guide now states that query responses will include the beneficiary’s most current Medicare ID, helping you confirm eligibility. Second, CMS has kept the $750 threshold for no‑fault claims as of January 1, 2026. In workers’ compensation, payers had until July 2025 to implement new reporting requirements, and the first CMPs related to workers’ compensation claims will not be issued until July 2026. These milestones give you a clear runway to update systems and training.

Data integrity is the real risk

Most industry articles focus on file submission mechanics. In practice, the bigger exposures come from data misalignment, especially across liability and workers’ comp lines. We have seen ORM termination dates in claim systems that don’t match what was reported to CMS. Liability programs often forget to report when they assume responsibility for medicals because they view themselves as “settlement only” payers. Settlements are sometimes reported at net values instead of gross amounts or with the wrong TPOC date. Internal disagreement between claims handlers, legal, and compliance over when ORM should start or end creates inconsistent reporting. Over‑reliance on a TPA, without clear oversight and audit rights, can mask these errors. And many organizations never designate a true MIR owner. When civil money penalties kick in, CMS won’t accept “my vendor handled it” as a defense.

Workers’ comp versus liability: know the differences

Workers’ compensation reporting tends to be structured and repetitive. Liability lines are fragmented, multi‑defendant, and defense‑driven. In personal injury and mass‑tort settlements, multiple carriers may share responsibility, and each has its own settlement documents. Insurers must report the claimant’s Medicare status and settlement details to CMS, and failure to comply can lead to hypervigilance with defense counsel. Attorneys often disagree on settlement dates, diagnosis codes, or the date of injury, which can create duplicate cases at CMS. CMS will treat mismatched data as separate events, leading to multiple recovery cases and potential garnishment of a beneficiary’s Social Security check. Liability programs should treat MIR compliance as integral to settlement planning.

Confirm your reporting structure

The first step in any audit is to ensure you know who is actually responsible for reporting. “RRE” status attaches to the entity that assumes primary payment responsibility. For captives, self‑insured retentions and fronted programs, the lines can blur. Verify that all subsidiaries and pooled entities with exposure are enrolled with CMS, and confirm that captives are not relying on a parent’s registration. Review all excess and deductible agreements to see whether the carrier, TPA, or employer has reporting duties. Ambiguity about responsibility is a penalty risk waiting to happen.

Sample and test your data

CMS plans to audit only 250 records per quarter, but you should perform your own audit on a larger scale. Pull a representative sample of open and recently closed claims across workers’ comp and liability lines, especially those involving Medicare beneficiaries. Compare the claim notes, payment histories, and settlement documents against what was reported to CMS. Pay particular attention to ORM start and end dates, TPOC dates, settlement amounts, and diagnosis codes. Variances usually surface first in ORM dates. This exercise will reveal process gaps and help you correct them before an auditor does.

Interrogate your ORM assumptions

In workers’ comp, ORM is usually clear: once you pay medical, you assume responsibility until you end it. Liability lines are trickier. The final rule penalizes untimely assumption of ORM, so you must examine how your program determines when medical responsibility begins. Did you pay a plaintiff’s medical bills before settlement? Did you agree to reimburse future medical expenses in the release language? Even if you never intended to manage medicals, those actions may create ORM, and they must be reported. Document your logic and coordinate with defense counsel so everyone agrees on the ORM effective date.

Make your TPOC records bulletproof

The total payment obligation to the claimant (TPOC) is often misreported because of inconsistent settlement practices. In multi‑defendant cases, each defendant must report its own gross settlement amount and ensure the dates align. CMS requires the gross amount, not a net after fees or liens, and the correct settlement date is the date of the written agreement or court approval. If funding is delayed, you must populate the “funding delayed beyond TPOC” field so that CMS doesn’t seek recovery before the claimant actually receives funds. Structured settlements and indemnity‑only agreements create further complexity. Review your settlement templates and train adjusters to capture all TPOC data elements accurately.

Account for new MSA reporting requirements

Starting in April 2025, CMS now requires payers to report not only the settlement amount but also the portion allocated to future medical care, often called the Medicare Set‑Aside (MSA) amount. Many employers and TPAs have not yet updated their systems to capture this figure. To stay compliant:

  • Work with your claims and legal teams to determine the MSA allocation during settlement negotiations and document it alongside the TPOC amount.
  • Coordinate with your reporting agent to ensure the MSA field is populated in your Section 111 file submission.
  • Implement periodic queries to confirm each claimant’s Medicare eligibility and cross‑check ORM dates, ICD‑10 codes, and TPOC amounts.

By preparing for this additional data field now, you can avoid last‑minute scrambles and reduce the risk of penalties when the new requirement is enforced.

Put governance front and center

Assign a single owner or committee to oversee MIR compliance. Provide regular reports to executive leadership so compliance is treated as an enterprise risk, not just an IT issue. Track rejection codes and error reports from CMS, look for trends, and require your TPA to provide detailed audit logs. Maintain documentation of all corrective actions and policy decisions. If you are unsure whether a settlement is reportable, consult counsel. Waiting until CMS sends a notice is costly and avoidable.

Get your lawyers in the loop early

Lawyers are not just litigators; they are essential compliance partners. Inconsistent data between plaintiff and defense attorneys can open duplicate cases and harm beneficiaries. Both sides will need to collaborate on key data points such as settlement date, diagnosis codes, date of injury, gross settlement amount, and funding date before submission. Using standardized forms and sharing drafts of Form B or settlement letters can prevent misreporting. Defense counsel should work with claims teams to confirm ORM status before negotiating a settlement, ensure release language matches the reported responsibility, and communicate settlement details to the reporting agent. Plaintiff counsel should reciprocate by aligning their lien resolution efforts with the defense’s reporting. Early communication reduces confusion, protects beneficiaries, and streamlines compliance.

Invest in an independent legal audit

Once you have cleaned up your data and processes, an independent legal audit becomes a powerful risk‑management tool. For high‑exposure programs like national employers, public entities, captives, and layered liability structures, external counsel can review your raw reporting data, sample claim files, and compare accident dates, ICD‑10 codes, and TPOC amounts against what was submitted to CMS. An audit will also evaluate whether your reporting agent or internal team is collecting the right information and sending it on time.

Unlike routine compliance checks, a legal audit delivers a defensible legal opinion on the correct dates of accident, injury description, and medical codes, and can uncover misclassified claims or inconsistent ORM termination dates. Counsel can also advise on safe‑harbor documentation and the new MSA reporting requirement. Viewed this way, a legal audit is not an extra cost; it is insurance against seven‑figure penalties and the reputational damage of noncompliance.

Final thoughts

Civil money penalties for MIR are no longer a hypothetical threat. CMS has built the rule and audit protocol to enforce them and has started random audits in 2026. The daily penalty has already been adjusted for inflation, and the audits will be random. Yet the biggest risk isn’t the dollar amount, it’s the operational and reputational damage that comes from poor data governance. Treat MIR compliance as enterprise risk management. Verify your RRE structure, test your data, interrogate your ORM assumptions, bulletproof your TPOC reporting, update your systems for MSA reporting and safe‑harbor procedures, invest in governance, and invite independent legal experts into the process. Organizations that take these steps now will be prepared when the first audit letters arrive; those that wait will be learning their lessons under penalty.