A one-vote House margin sent deep Medicaid reductions to the Senate, while CMS escalated Medicare Advantage oversight and a ransomware attack shut down an Ohio system.
May set the terms for the rest of the year. Congress moved the largest Medicaid financing changes in a generation one step closer to law, CMS signaled a much tougher posture toward Medicare Advantage coding, and a regional health system offered a fresh lesson in what a systemwide cyber outage looks like.
House passes the reconciliation bill by a single vote
On May 22 the House approved the budget reconciliation package, now known as the One Big Beautiful Bill Act, 215-214. For hospitals, the core provisions limit two financing tools states lean on to fund Medicaid: provider taxes and state-directed payments. The AHA put the reduction in federal Medicaid support at more than $700 billion over ten years and warned that millions of people would lose coverage. The bill also pulls forward Medicaid work requirements for adults ages 18 to 64, with states required to implement them no later than the end of 2026.
Hospital groups pushed back hard, arguing that supplemental payments offset years of Medicaid underpayment rather than representing waste. The bill now goes to the Senate, where changes are expected.
CMS moves to audit every eligible Medicare Advantage contract
On May 21 CMS announced it would conduct risk adjustment data validation (RADV) audits of all eligible MA contracts each year, up from roughly 60, and finish the backlog for payment years 2018 through 2024 by early 2026. To get there, the agency said it would grow its medical coding staff from about 40 to roughly 2,000 by September, and review up to 200 records per contract depending on plan size.
The audits target plans, not hospitals, but systems should expect the effects to land on them. Plans facing clawback risk tend to tighten documentation requests, coding reviews and payment disputes with providers. Systems that own or partner with MA plans carry direct exposure.
Kettering Health ransomware attack forces systemwide outage
On May 20 Kettering Health, which runs 14 medical centers and more than 120 outpatient sites in western Ohio, suffered a cyberattack that took down its technology systems. The system canceled elective inpatient and outpatient procedures and lost its call center, and scammers posing as Kettering staff called patients seeking card payments. Emergency care continued.
The event is a reminder that downtime planning has to cover more than the EHR: patient communications, scheduling, fraud warnings to the community and the financial hit from canceled cases all need owners before an incident, not during one.
Executive takeaway: Model your Medicaid supplemental payment exposure now under the House bill and a harsher Senate version, and confirm your downtime plan covers patient communications and canceled-case revenue.
Sources