Earlier this year, CMS posted an RFI on its "CRUSH" anti fraud scale-up. CMS has generated a proposed rule now percolating at OMB. This week, CMS pivots to its categories of fraud contractors (eg UPIC) and asks for YOUR views on them.
Blog by Chat GPT.
###
CMS Seeks a New Fraud-Defense Contracting Model, Alongside Pending CRUSH Rulemaking
CMS has opened a new request for information on how to structure its fraud-defense contracts, inviting ideas that could substantially reshape the agency’s investigative operations. Published October 5, 2026, the SAM.gov notice, “Request for Information – Fraud Defense Contracts,” carries Notice ID 270536.
Responses are due November 4, 2026, at 11 a.m. Eastern Standard Time.
Kimberly Brandt, CMS Deputy Administrator and Chief Operating Officer, highlighted the initiative in a LinkedIn post. Her message describes a reassessment of a longstanding contracting model in light of new technologies and investigative techniques, with an emphasis on detecting and preventing fraud before payments leave the government.
The notice comes with two substantive attachments: a six-page Draft Fraud Defense Contracts Statement of Objectives and a 41-page Interested Vendor Response form. Both are available through the SAM.gov notice. Together, they offer a detailed view of the operating model CMS is considering.
The CRUSH Context: Regulatory Policy and Investigative Operations
The new RFI should be read alongside CMS’s earlier CRUSH request for information, published February 27, 2026, at 91 FR 9803. CRUSH stands for Comprehensive Regulations to Uncover Suspicious Healthcare.
That earlier request sought feedback on potential regulatory and programmatic changes, including provider enrollment, payment suspensions, ownership verification, medical review, and data analytics. Its comment period closed March 30.
CRUSH has since advanced to a draft proposed regulation under White House review. As of October 7, OMB’s public listing identifies the CRUSH proposed rule, CMS-6098, as pending, with a received date of August 7, 2026. The listing does not disclose the draft text or establish a publication date. An earlier Discoveries in Health Policy discussion reviewed that regulatory progression.
The October contracting RFI addresses a related operational question: how should CMS organize the people, technology, investigative responsibilities, and financial incentives that make program-integrity policy work? It is a procurement-planning exercise and does not itself change regulatory authority or award a contract.
The Central Change: CMS Would Drive the Investigative Agenda
The draft Statement of Objectives gives CMS the primary role in proactive data analysis, lead generation, prioritization, and law-enforcement vetting. Approved investigations would then be assigned to contractors for development.
Contractors would supply investigative, clinical, analytical, and management expertise. Their work could include targeted prepayment or post-payment medical review, onsite investigations, interviews, evidence collection, and support for payment suspensions, billing-privilege revocations, and law-enforcement referrals. They would also support appeals, hearings, testimony, and litigation.
Contractors could still develop leads, but only as capacity permits and through CMS review and direction before opening an investigation. CMS-assigned work would take priority.
The document repeatedly emphasizes timely, consistent, and defensible action. It also requires records in CMS-designated systems and continuity during contractor transitions. The proposed model therefore concerns control of the investigative pipeline as much as the introduction of new technology.
What the Response Form Reveals
The accompanying form asks questions that reach well beyond incremental improvements to existing Unified Program Integrity Contractor, or UPIC, arrangements.
Centralization and specialization. CMS asks whether medical review, law-enforcement assistance, site verification, and other functions should be centralized or assigned separately. It also seeks views on national specialty contractors focused on particular provider types, and on jurisdictions and field offices capable of handling investigations across geographic boundaries.
Responsibility across the contractor network. The form asks where handoffs among program-integrity contractors, Medicare Administrative Contractors, Recovery Audit Contractors, and the Supplemental Medical Review Contractor delay or weaken administrative action. CMS is explicitly inviting suggestions for redrawing responsibilities.
Medicare Advantage, Part D, and Medicaid. CMS asks whether Part C and Part D investigations should be integrated with fee-for-service investigations. Although the draft Statement of Objectives focuses on Medicare, the form separately considers Medicaid strategy, including the consequences of separating Medicare and Medicaid investigations, managed-care encounter data, and coordination with state Medicaid agencies and Medicaid Fraud Control Units. These are questions under consideration, rather than announced decisions to separate the programs.
Technology and AI governance. The questions cover analytics, modeling, AI, open-source intelligence, complaint intake, and information sharing. They also ask about explainability, human review before action, model validation, ownership of tools and work products, and portability when a contract ends. Under the draft, contractors would need CMS approval before using non-approved AI, automation, external data resources, or material process changes.
Performance and provider safeguards. CMS seeks measures of quality, timeliness, preventable financial loss, and enforcement outcomes. It also asks how to limit false positives and unnecessary provider burden, and protect beneficiary access when a provider is suspended or revoked. Another question asks how investigative findings should feed back into prepayment edits, enrollment screening, and policy changes.
Fixed-Price Contracting Is an Explicit Part of the Agenda
The form cites Executive Order 14402, Promoting Efficiency, Accountability, and Performance in Federal Contracting, and asks about fixed-price, fixed-unit-price, and hybrid arrangements.
This raises a practical challenge. Investigations vary in complexity, staffing needs, duration, and dependence on government decisions. CMS therefore asks what workload information, systems access, and service-level commitments vendors would need to price the work.
The agency also asks which activities are poorly suited to fixed-price contracting and how incentives can avoid rewarding the volume of investigations, referrals, or administrative actions over their quality. Similar concerns appear in the Medicaid performance questions.
CMS is seeking a payment structure that supports useful, defensible results without creating an incentive simply to produce more cases.
Reading Between the Lines
Several reasonable inferences emerge from the documents, although none establishes a final procurement decision.
CMS appears to be considering a substantial redistribution of responsibilities. The repeated emphasis on CMS-generated leads, centralized functions, specialty contractors, and revised jurisdictions suggests a reassessment of the existing operating model. The notice specifically invites respondents to think beyond current UPIC statements of work and traditional manual processes.
The questions suggest interest in broadening the vendor market. CMS explicitly asks what prevents commercial special-investigations units and analytics firms from competing. Its questions about tool ownership and portability also suggest concern about retaining government access to capabilities when contractors change. For incumbent vendors, investigative execution and responsiveness may become more important competitive differentiators if CMS assumes more of the lead-development role.
Greater central control could improve coordination while creating new bottlenecks. Question 7 asks what decision timelines, data access, and approvals CMS itself must commit to so contractors can meet performance standards. That is an unusually revealing acknowledgment: contractor speed depends partly on government speed.
Specialty expertise may gain importance. National contractors organized around provider types could offer deeper understanding of complex billing and clinical practices. Laboratories and advanced diagnostics are plausible examples where specialization could matter, but the RFI does not announce a laboratory-specific contract.
These interpretations point toward a broader redesign of investigative operations, while leaving the actual contract structure, budget, awards, and implementation timetable unresolved.
How to Respond
CMS instructs respondents to email only the completed Attachment 3.2, Interested Vendor Response, to contracting officer Jennifer Kuhn by 11 a.m. EST on November 4, 2026.
All organization-related information must be completed, but respondents may answer some or all questions. Each answer is limited to 4,000 characters, including spaces. CMS expressly states that this is not a request for capability statements.
No contract will be awarded from this RFI. Participation or nonparticipation will not affect evaluation of responses to a later solicitation, and CMS will not reimburse response costs. The agency may follow up with individual respondents.
For stakeholders tracking CRUSH, the contracting documents provide a useful companion to the pending rule: they show how CMS is considering reorganizing the investigative machinery that supports fraud prevention and enforcement.
##
Sidebar:
Why Post at SAM.gov—and Will the Responses Be Public?
The venue reflects the task: CMS is planning contracts. The earlier CRUSH RFI sought input on possible regulatory and programmatic changes through the Federal Register and Regulations.gov. This RFI asks how CMS should buy and manage investigative services. SAM.gov is the normal procurement venue for that kind of industry outreach. FAR 15.201 expressly permits RFIs to collect market information for planning, without awarding a contract.
Email submissions also fit that process. A contracting officer can collect structured vendor feedback and conduct follow-up discussions. In this case, CMS specifies a response form, directs submissions to its contracting officer, and reserves the right to follow up individually.
The responses should NOT be assumed to become a public comment docket. The supplied notice and attachments do not announce plans to publish individual submissions. The reasonable expectation is that CMS will review them internally, rather than routinely post them as Regulations.gov comments. That remains an inference; CMS has not expressly stated its publication policy.
However, email submission does not guarantee confidentiality. FAR 15.207(b) requires safeguarding RFI information from unauthorized disclosure, but that is not a blanket exemption from lawful disclosure. Agency records can be requested under FOIA, with trade secrets and qualifying confidential commercial or financial information potentially protected. FAR Subpart 24.2 discusses these protections. The separate protection for proposals submitted to competitive solicitations should not automatically be assumed to cover this preliminary RFI.
A plausible practical advantage is more candid vendor input: firms can discuss pricing assumptions, operational weaknesses, and technology without routinely displaying those details to competitors. Nothing in the documents establishes that avoiding public scrutiny motivated CMS’s choice.
