By Justin Romine and Heather Sanderson
Imagine receiving a notice from Centers for Medicare & Medicaid Services (CMS) questioning whether your organization reported a Medicare-related claim on time. Could your organization reconstruct the decision, produce supporting documentation, identify who owned each step, and demonstrate that effective controls are in place? For many claims organizations, the answer may be uncertain. As CMS moves to active Section 111 enforcement, reporting deficiencies that once seemed administrative can now reveal broader weaknesses in governance and enterprise risk management.
For years, Section 111 Medicare Secondary Payer (MSP) reporting has largely been viewed as a compliance obligation supported by education and technical guidance from the Centers for Medicare & Medicaid Services (CMS).
For those unfamiliar, Section 111 reporting is a federal reporting requirement under the Medicare Secondary Payer (MSP) Act that requires Non-Group Health Plan (NGHP) Responsible Reporting Entities (RREs)—including workers' compensation insurers, liability insurers, no-fault insurers, and self-insured entities—to electronically report certain claims involving Medicare beneficiaries to the CMS. CMS uses this information to ensure Medicare pays for medical expenses only when appropriate, to identify situations where another payer has primary payment responsibility, and to facilitate recovery of conditional payments when Medicare has paid expenses that should have been covered by the NGHP.
While reporting requirements have always carried the potential for enforcement, CMS historically focused on helping Responsible Reporting Entities (RREs) improve their reporting processes rather than penalizing reporting mistakes. That approach is beginning to change.
In 2026, CMS took a significant step by conducting its first-ever Civil Money Penalty (CMP) compliance audit of a Non-Group Health Plan (NGHP) Responsible Reporting Entity. Shortly after that audit concluded, it appears CMS issued at least one CMP notice involving allegations of untimely Section 111 reporting. Although CMS has not publicly identified the organization involved, the message to the industry is clear: Section 111 reporting has entered an era where enforcement is no longer theoretical.
CMS is now conducting its second quarterly CMP audit, and additional enforcement notices may soon follow. While the number of audits and penalty notices remains relatively small, the significance lies less in the volume than in the precedent being established. CMS has demonstrated that it is prepared to use the enforcement authority Congress provided, and organizations should expect that oversight will continue to increase.
For insurers, self-insured organizations, third-party administrators, and claims professionals, this shift should prompt a fresh look at Section 111 compliance programs.
Enforcement Does Not Necessarily Mean Punishment
The recent enforcement activity has understandably generated concern throughout the claims industry. However, CMS has also been careful to clarify that a CMP notice should not automatically be viewed as the beginning of a punitive action.
Agency representatives have explained that the notice process is intended to create an opportunity for dialogue. Organizations receiving a notice can respond, explain the circumstances surrounding the alleged reporting deficiency, and demonstrate the compliance efforts already in place. In other words, CMS appears interested in understanding why a reporting issue occurred before determining whether penalties are ultimately warranted. That distinction is important.
What Claims Organizations Should Be Doing Now
Top performing claims organizations regard Section 111 reporting as a core element of enterprise risk management rather than administrative function. The current enforcement environment provides an excellent opportunity to evaluate existing Section 111 compliance efforts to determine whether they can withstand an audit and confidently prove that every reportable claim was compliant.
Many reporting issues are not caused by a misunderstanding of the law. The greatest exposure often stems not from intentional non-compliance, but from breakdowns in processes such as inaccurate claimant data, missed Medicare beneficiary identification, delayed Ongoing Responsibility for Medicals (ORM) or Total Payment Obligation to Claimant (TPOC) reporting and insufficient documentation of compliance efforts. Organizations must be able to demonstrate not only that reportable events were submitted, but that they were accepted by CMS and supported by defensible records.
Thoughtful claims leaders are partnering with their MSP partners to conduct proactive Section 111 audits. These audits should focus on data quality and the coordination of various hand-offs between claims teams, systems administrators, and vendors to identify potential weaknesses before CMS does. Internal policies and procedures should be reviewed regularly to ensure they reflect current CMS guidance and operational realities. Ongoing training is equally important, particularly as reporting personnel change roles and CMS continue refining its expectations. Identifying subject matter experts within your organization who have a passion for Medicare compliance should be leveraged to stay ahead of new developments, train others and participate in the audit process.
Executive oversight also matters. Organizations should be able to demonstrate that reporting responsibilities are clearly assigned, quality assurance measures are in place, reporting errors are investigated, and corrective actions are documented. These governance measures not only improve reporting quality but also help establish the good-faith compliance efforts that CMS has repeatedly indicated it wants to see.
Looking Ahead
The first CMP audit marks more than an isolated enforcement action, it represents a turning point in the evolution of Section 111 reporting.
CMS appears to be taking a measured approach, balancing education with accountability. The agency has made clear that it wants organizations to succeed, but it has also demonstrated that reporting obligations will no longer rely solely on voluntary compliance.
For claims organizations, the takeaway is straightforward. Section 111 reporting should be viewed as a core compliance function deserving the same level of attention as claims handling, data security, or regulatory reporting. Organizations that proactively strengthen their compliance programs today will be far better positioned to navigate increasing regulatory scrutiny tomorrow.
As CMS continues expanding its audit activities, the best prepared organizations will be those that have invested in strong internal controls, regular compliance reviews, comprehensive training, and a culture that treats accurate Section 111 reporting as an enterprise-wide responsibility, not simply another claims administration task.
About the authors
Justin Romine is vice president, global claims at Marriott International. Justin.Romine@Marriott.com
Heather Sanderson is CEO of Sanderson Firm PLLC. Heather@sandersoncomp.com.