When CMS opened its Medicaid Enterprise Systems (MES) IT Standards RFI, it asked the health and human services community to help shape how the next generation of Medicaid technology gets built: modular, interoperable, and standards-based.

Verato® submitted a response because we believe one capability is missing from that conversation. It’s one every state Medicaid leader will eventually run into, whether through a new federal mandate, an audit finding, or a caseworker who can’t find the right record.

That capability is accurate, real-time identity resolution: the ability to consistently recognize that a beneficiary, provider, or organization record in one system is the same person or entity as a record in another.

It’s easy to assume this is solved already. Data exchange standards like HL7 FHIR tell systems how to format and move information, and most states have invested heavily in exactly that kind of interoperability. But formatting data correctly and knowing who it belongs to are two different problems. A perfectly standards-compliant record can still land on the wrong person’s file, or fail to match at all, if the receiving system can’t confirm the identity behind it.

We’ve come to think of this as the “identity gap:” the space between systems exchanging data cleanly and systems actually knowing who that data is about. Closing it isn’t a byproduct of better interoperability standards. It requires a dedicated, accurate matching capability built into the MES architecture itself.

The stakes are not abstract. Medicaid generated $31.1 billion in federal improper payments in fiscal year 2024. Of that, 79% traced back to missing or insufficient documentation, much of it rooted in eligibility and identity verification gaps rather than fraud alone.1

Now, the pressure is only increasing: H.R. 1 requires states to run quarterly deceased-status checks starting January 1, 2027, detect duplicate enrollment across state lines, and verify new work requirements, all of which depend on the same underlying capability.

This is not a one-time deadline to clear. Roughly every two to three years, a new federal rule asks states to exchange or verify person data in a new way. States that build identity resolution as reusable infrastructure meet each new requirement by extending a capability they already have. States that treat it as a one-off feature inside a single module end up rebuilding the same work, under a new deadline, every time.

We’ve seen what it looks like when a state gets this right. One state Medicaid agency that shares eligibility data across Medicaid, SNAP, and TANF reduced its cross-program duplicate rate from roughly 24% to under 2% after replacing fragmented, system-by-system matching with a single, reusable identity resolution service.2 That same service is now being extended to meet new federal mandates without rebuilding matching logic from scratch, exactly the kind of durability CMS’s modularity vision is asking for.

In our response to CMS’s RFI, we recommended that they build on their own move toward outcomes-based certification under Streamlined Modular Certification by:

  • Defining identity-resolution outcomes, such as duplicate-rate ceilings or cross-module match-rate floors, within the Member Management and Provider Management domains of the SMC Intake Form
  • Encouraging states to implement identity resolution as a shared, reusable enterprise service rather than logic duplicated inside every module
  • Standardizing the identity data elements and matching expectations that support cross-state data exchange, including the data behind the new national duplicate-enrollment database
  • Requiring standardized, auditable identity resolution as a data-quality prerequisite for AI-driven Medicaid use cases
  • Pairing consent and access management standards with an explicit identity resolution requirement, since consent decisions are only as good as the identity behind them

For state Medicaid and human services leaders, the takeaway isn’t about any particular vendor or product. The next round of federal mandates, and the one after that, will keep asking the same underlying question: can your systems tell, with confidence, that this is the same person? States that answer that question once, with the right foundation, will spend less time and money answering it again every time the rules change.

If your state is weighing how to approach identity resolution as part of MES modernization, or wants to see how this played out in practice, see how one state Medicaid agency cut its cross-program duplicate rate from 24% to under 2% with Verato. And if you’d like to talk through what this could look like for your state’s own MES roadmap, we’d welcome the conversation. Contact us anytime.


1U.S. Centers for Medicare & Medicaid Services (CMS), Fiscal Year 2024 Improper Payments Fact Sheet, November 2024.

2Verato replaced fragmented, homegrown identity systems as the identity foundation for Mississippi Division of Medicaid’s beneficiary portal (Verato case study, 2026).

We’ve built the identity foundation that gets patient data right from day one

See the platform, or talk to our team.