One Consulting Firm Runs the Software That Decides If You Get Medicaid. Twenty-Five States Bought It.
The fight over AI denying care keeps pointing at insurers. The software deciding whether you qualify at all is older, dumber, and one contractor runs it across half the country.
Years ago I helped build a rules engine — the unglamorous middle layer that takes a form on one side and produces a decision on the other. Somewhere inside it was a boolean field, and like every boolean field ever written, it had a default. If nobody set it, it was false.
Not "unknown." Not "please go check." False.
The argument about that default lasted maybe ten minutes, and then I lost interest, because the stakes were low and the deadline was not. I've thought about that field constantly these past few weeks, because a field very much like it appears to have decided that a woman in Michigan was not disabled — and therefore earned too much to qualify for coverage she was entitled to. The system did not conclude she was ineligible. It never learned she was eligible. Different failures, and only one is visible from outside.
First, the part nobody is actually arguing about
The ground floor is contested by no one — not the reporters, not the states, not the company.
Deloitte has operated Michigan's Medicaid eligibility system — the thing that decides who is in and who is out — under contracts worth roughly $768 million since 2006, according to contracts reviewed by KFF Health News. Twenty years. One vendor. One state.
Now widen the frame. The KFF Health News investigation counts twenty-five states that have awarded Deloitte contracts for eligibility systems — agreements in which the company commits to design, develop, implement or operate state-owned systems, and which are worth at least $6 billion, dwarfing any of its competitors. NPR's version says "at least 25 states." A federal complaint filed in January 2024 counted at least 20. Deloitte's own Michigan bid documents cited work on similar systems in 31 other states: "Michigan benefits from our technical expertise drawn from across the nation." Four counts, four parties, different definitions — not a growth curve. What they add up to is a market with one dominant seller sitting between roughly half the country's Medicaid applicants and their coverage.
And here is what's gone under-covered. The public fight about AI in health care is almost entirely a fight about claim denial — the insurer, the algorithm, the treatment refused. That fight is real, and it starts one step too late. Before anyone can deny your claim, something has to decide you're a person with coverage at all. In most states that is done by software older and dumber than anything you'd call AI: a rules engine, and a database that has to know things about you. It's invisible, because when it fails it produces a letter identical to the one it would have produced if it had worked.
What the failure actually looks like
The KFF Health News investigation found that Michigan's system has incorrectly directed people with disabilities into skimpier benefits that cover limited care, or denied coverage completely.
Notice the shape. The headline failure mode isn't a slammed door; it's a quiet downgrade — still "covered," just not for what you need. Harder to notice, harder to appeal.
In the case at the center of the reporting, documents reviewed by KFF Health News and interviews with the applicant and the attorney who helped her indicate that the state's computer system did not register that she is disabled, and said she earned too much to qualify — what those documents and people indicate, not a finding by an auditor or a court. Anastassia Kolosova, the Disability Rights Michigan attorney who helped her, gave the systemic version: "There's something wrong with the system if they're relying on individual caseworkers to catch this."
Michigan's Department of Health and Human Services responded that it "is not aware of any widespread or systemic issues" within Bridges related to disability-based eligibility pathways. Read that twice. It's a statement about the department's knowledge, not a statement that no such issues exist — and in a system whose defining property is that its errors are hard to see, those are very far apart.
The state's own auditor said this out loud sixteen years ago
A Michigan Auditor General report in 2010 said state agencies did not provide effective project administration for Bridges and — the line I keep rereading — that the state could not independently maintain and operate the system because "the contractor did not transfer knowledge and skills" to state officials. Dependency wasn't something Michigan drifted into. It was audited and named while the system was young.
That audit also found Deloitte's original contract, valued at roughly $70 million, "ballooned by $50 million over the initial cost, a 71% increase." State records show millions more were added, bringing that contract to $124.1 million. (The 71% is the auditor's; the $124.1 million comes from state records via KFF Health News.) The latest Michigan contract is worth $197.4 million and runs to 2030.
In fairness, Michigan says the state "is now fully capable of operating and maintaining Bridges independently" — a 2026 spokesperson's assertion against a 2010 audit finding, with no independent check on either. The only two data points here are sixteen years apart and point opposite ways.
Tennessee, where a judge wrote it down
Tennessee is what happens when somebody finally does audit one, through a courtroom.
Medicaid beneficiaries sued Tennessee in 2020, alleging the state's Deloitte-built system "does not reliably test for eligibility" for several categories of people with disabilities. Thirty-five children and adults from across Tennessee brought that class action over wrongful terminations of TennCare coverage. Deloitte's contract there is worth $1.12 billion over a decade.
On August 26, 2024, a federal court ruled for the enrollees. Plaintiffs' counsel says the ruling establishes that TennCare violated enrollees' rights under the Medicaid Act, the Constitution's Due Process Clause, and the Americans with Disabilities Act. Coverage of the decision described thousands of Tennesseans illegally denied Medicaid and other benefits because of programming and data errors in an algorithmic system the state uses to determine eligibility. That system, TennCare Connect, was "built by Deloitte and other contractors for more than $400 million" — other contractors, plural; not one firm's system.
The technical findings belong tattooed inside every procurement officer's eyelids. The court found that TEDS, the eligibility system at the center of the case, did not consistently load relevant eligibility data, "such as receipt of Social Security benefits, disability status or marital status." It also found some enrollees were put into the wrong households or dropped from their correct households, so renewal notices went to incorrect addresses. Per the 116-page opinion of U.S. District Judge Waverly Crenshaw, the program violated the Medicaid Act, the Fourteenth Amendment and the Americans with Disabilities Act.
Sit with that. The machine didn't weigh your disability and decide it wasn't enough; it never loaded your disability. And the letter telling you to act went somewhere you don't live.
The court's own summary is the sentence I can't shake. Poor, disabled and otherwise disadvantaged Tennesseans, it wrote, "should not require luck, perseverance, or zealous lawyering to receive healthcare benefits they are entitled to under the law." And on the state's knowledge: "TEDS is flawed, and TennCare knows that it is flawed."
Here's the accountability fact in the middle of all this, stated exactly: the lawsuit does not name Deloitte as a defendant. That is not the same as saying Deloitte was cleared. No court found the company not liable, because no court was asked. The state was sued and found to have violated three bodies of law; the firm that wrote the code was not a party.
So who is holding anyone to account?
One: that court decision, in a case where the vendor was not a defendant.
Two: a complaint filed with the Federal Trade Commission in January 2024 by the National Health Law Program, EPIC and Upturn, alleging Deloitte "has engaged in unfair and deceptive trade practices… in violation of Section 5" of the FTC Act. Everything in it is an allegation — a filing, not a finding. It states Deloitte contracts with at least 20 states for eligibility software, and alleges the company "has been aware of similar accuracy issues with its automated benefits eligibility systems in other states for several years" without meaningful steps to mitigate the same harms in Texas. They later sent further information to supplement and support the complaint. In the two and a half years since, no public action. Not a dismissal, not a rejection — an absence.
Three: four letters. On October 10, 2025, four senators wrote to Deloitte, GDIT, Gainwell Technologies and Conduent — the companies the Centers for Medicare & Medicaid Services identified as eligibility system contractors. Spokespeople for the four companies did not provide comments for that story.
That's the list. Worth knowing whose money is at stake meanwhile: the federal government covers 90% of states' costs to develop and implement state Medicaid eligibility systems, plus 75% of maintenance and operations. Whether or not you're on Medicaid, you're paying for nearly all of this software.
And none of it started with AI
I don't want to sell you a story about robots. In 2016, nearly half of beneficiaries in Arkansas's Medicaid home and community based services program experienced unexpected and dramatic cuts to their care after the state adopted a scoring instrument — an arithmetic formula, not machine learning; calling it AI would flatter it. After a federal court found the state had violated due process requirements, it "suspended care reductions for several months and revised its notices of adverse action." The fix for an unexplainable scoring system was a better-worded letter.
Scale is what's new. TechTonic Justice, founded by the litigator from that Arkansas case, estimated in November 2024 that 73 million low-income people are exposed to AI-related decision-making in Medicaid — through eligibility and enrollment, home- and community-based services determinations, or prior authorization. "Exposed to" is not "decided by," the definition of AI is deliberately broad, and the number comes from an advocate rather than a government — but nobody in Washington produces a competing count. The same report cites four million Texans facing the potential loss of insurance through "a labyrinthine Medicaid enrollment system that even agency staff cannot navigate." Four million Texans did not lose coverage. Four million Texans are standing in the blast radius of a system nobody can steer.
Now the part that complicates my own argument
If I stopped here I'd have written a hit piece. So — the other side, at its strongest.
Deloitte's answer, in its own words, is narrow and specific. Spokesperson Karen Walsh said in an emailed statement that it found "no system anomalies causing routine denials of Medicaid for people with disabilities." Notice what that claims and doesn't: it denies system anomalies causing routine denials, not that any individual was wrongly denied. Carefully bounded — which is why I quote it rather than summarize it.
The company also makes a structural argument that is the strongest thing anyone has said in this debate: "All of the eligibility systems we support are owned by the states and built to their unique specifications. We will continue to work at the direction of our state clients." Kenneth Smith, the executive who leads Deloitte's national human services division, has said the technology is state-owned and that agencies direct its operation and set the policies — "They're not Deloitte systems," four words the accountability argument has to get past. Deloitte adds that "There are many reasons why someone may no longer be eligible for a benefit they once received or believe they deserve," which is simply true. Not every denial is an error.
That defense isn't spin. Eligibility rules are set by state and federal policy, not by a vendor — and software implementing a rule faithfully isn't the villain if the rule is what excludes you. (The reporting flags this as a previously stated position, not a fresh response.)
Second complication, and it nearly reversed my view of the piece: automation is not the variable.
A peer-reviewed Health Affairs study examined an intervention that showed four states — California, New York, South Carolina and Wisconsin how to process more renewals automatically. Between them those states account for close to a third of Medicaid enrollment. Against other states, ex parte renewals rose 21.6 percentage points, overall renewals 7.7 points, and procedural denials decreased by 8.3 points. The authors: "Reducing burdens by automating Medicaid renewals ensures that eligible beneficiaries remain in the program."
More automation. Fewer wrongful losses of coverage — the opposite of my opening story, and better evidenced.
And here's the detail that made me rewrite two sections: Pamela Herd, the University of Michigan researcher who is first author of that study, is also the expert warning in the Michigan coverage that "when these administrative systems get overloaded, everyone gets impacted." Same scholar. Both things.
So the honest framing is neither "automation good" nor "automation bad." Automation amplifies whatever the system already is: point it at removing paperwork from people's lives and it keeps eligible people covered; point it at policing them and you get what you'd expect. (One limit: that study is about automating renewals, not the engines that decide your case in the first place. Cousins, not twins.)
Third, there's a serious fiscal argument on the other side. The right-of-center Paragon Health Institute estimates 9.2 million Medicaid expansion enrollees — 46 percent of the total — were likely ineligible in 2024 under its central assumptions, and that improper enrollment cost the federal government an estimated $32.9 billion. Keep "likely" — an estimate built on assumptions, not a count. Paragon's argument is that Medicaid's financing structure weakens states' incentives to determine eligibility accurately; I won't put a snappier claim in its mouth.
The Foundation for Government Accountability makes the operational version: states, it argues, can require documentation of eligibility factors such as access to other coverage and residency, and decline post-enrollment verification for income. Separately: "States should also cross-check data between welfare programs to identify ineligible enrollees and fraud." Hold that sentence. We meet it again shortly, wearing an Australian accent.
Fourth — and this cuts both ways, which is why I trust it — the nonpartisan KFF explains that the Medicaid error rate everyone quotes is not a "fraud" rate but "a measurement of payments made that did not meet statutory, regulatory, or administrative requirements." Medicaid paid an estimated 93.9% of outlays properly in 2025. So much for one-in-five-dollars-is-fraud. But the brief won't let my side off: most improper payments — 77.2% in 2025 — are due to insufficient documentation. Paperwork: what an eligibility engine automates, and where it fails. And nearly a quarter of states already sit above the three percent PERM threshold.
Finally, the structural objection to this whole article: maybe the contractor is a red herring. Research on administrative burden calls it the kind of "onerous encounters that we have not infrequently with public services and benefits or with the government more broadly" — a property of bureaucracy itself, whose burdens "affect groups unequally and are especially hard on people lower in socioeconomic status or socially excluded groups," software or no software. Even the plaintiff-side National Health Law Program calls this a promise "often not realized" — often, not always; unmet, not a lie.
Australia ran this experiment already. Then it ran an inquiry with subpoena power.
Australia didn't merely make this mistake. It made it, got caught, and then did something the United States has shown no capacity to do.
The scheme was Robodebt. The mechanism was insultingly simple: it compared a person's averaged annual income against what they actually reported while receiving payments, and when the two diverged, a debt notice was automatically issued to welfare recipients. No caseworker. Averaging, subtraction, a letter. It also, as the Blavatnik School of Government's account puts it, had "the effect of reversing the onus so welfare recipients had to disprove overpayment." A$746 million was wrongfully recovered from 381,000 individuals and later refunded.
Which is the moment to revisit that proposal to cross-check data between welfare programs — data-matching being the precise mechanism that produced Robodebt. Australia had authorized it in statute long before anyone said "AI": section 6A of the Social Security (Administration) Act 1999, inserted in 2001, provides that the "Secretary may arrange for use of computer programs to make decisions."
Robodebt ran for years. It ended in mid-2020, and the Australian Government's own formal response is blunt about why: "Not because the former government saw the error of its ways or finally came to its senses." It ended because the Federal Court found the scheme unlawful. A court, not a conscience. Sound familiar?
Now the part with no American equivalent. In August 2022 Australia established a Royal Commission under Commissioner Catherine Holmes. Eleven months later, on July 7, 2023, its final report found the scheme produced inaccurate results and did not comply with the income calculation provisions of the Social Security Act. Somebody with subpoena power named the statute the software broke. Nobody in the United States has done that.
The report reads less like a technical document than an indictment. Robodebt was "a crude and cruel mechanism, neither fair nor legal, and it made many people feel like criminals." The Commissioner wrote, in her own voice, that "it is remarkable how little interest there seems to have been in ensuring the Scheme's legality, how rushed its implementation was, how little thought was given to how it would affect welfare recipients and the lengths to which public servants were prepared to go to oblige ministers on a quest for savings." What she found "truly dismaying was the revelation of dishonesty and collusion to prevent the Scheme's lack of legal foundation coming to light." She dated the knowledge precisely: the beginning of 2017 was when Robodebt's "unfairness, probable illegality and cruelty became apparent." Probable illegality — her word, kept, because the Federal Court's finding of unlawfulness is a separate and harder fact.
Then the Australian prime minister quoted that indictment back to the country, including the finding that it was "a costly failure of public administration, in both human and economic terms" — repeated, not contested. Compare "not aware of any widespread or systemic issues."
The Commissioner also told the Governor-General she had provided "an additional chapter of the report which has not been included in the bound report and is sealed. It recommends the referral of individuals for civil action or criminal prosecution." Accountability was a deliverable — referrals, per the official overview, "to hold those individuals to account."
The follow-through was partial, and you get the unflattering half too. Three years later Australia's national anti-corruption commission revealed the identity of the referred people: five bureaucrats and former prime minister Scott Morrison, who was social services minister at the time. Two of the six — Mark Withnell and Serena Wilson — "had committed serious corrupt conduct." Morrison "did not engage in serious corrupt conduct," being entitled to rely on departmental advice. Nobody was jailed; the top of the chain came out clean.
On policy: the Commission made 56 recommendations and one closing observation (not 57; the press miscounts the observation as a recommendation), and the government "accepts or accepts in principle all 56 recommendations." It declined the observation, concluding section 34 of the freedom-of-information law should not be repealed — so even the accountable jurisdiction kept its cabinet documents shut.
Two recommendations should keep American procurement officers awake. Recommendation 17.1: a consistent legal framework for automation in government services, and "business rules and algorithms should be made available, to enable independent expert scrutiny." Recommendation 17.2: a body "with the power to monitor and audit automated decision-making processes."
Both begin "should consider." The government "has committed to considering opportunities for legislative reform" and "agreed to consider the establishment, or expansion, of a body." Australia has not legislated algorithmic transparency for benefits systems, and no such regulator exists as far as I can establish. Its Attorney-General's Department did identify 46 instances of primary legislation authorizing automated decisions — so Australia at least knows how many statutes let a computer decide.
In June 2026, six years after the scheme ended, the Commonwealth agreed that it will pay $548.5 million in an approved class action settlement — which the plaintiffs' firm says brings the combined value of settlement, repayments, restitution and abandoned debts across both class actions past $2.4 billion. (Plaintiffs' lawyers' figures, measuring different things; don't add them together.)
Australia's incomplete accountability — subpoena power, a named statute, published names, 56 recommendations answered in writing, and still no legislated algorithmic transparency — is dramatically better than our complete absence of it.
Just imagine: the letters go out in January 2027
Let me run the clock forward — the next chapter is already scheduled.
The 2025 reconciliation law requires 44 states, including DC, to condition Medicaid eligibility for adults in the ACA expansion group and certain 1115 waiver enrollees on meeting work requirements starting January 1, 2027. States must implement by that date, though they may choose to do so sooner through 1115 waivers. (It is January 1, 2027. Several summaries circulating say December 31, 2026. They're wrong.)
So every affected state has months to teach an old rules engine a new category of rule — one needing month-by-month knowledge of a person's employment, hours, exemptions and documentation. The companies paid millions in taxpayer funds to make those changes include Deloitte, Accenture and Optum, and the changes are projected to strip Medicaid from roughly 7.5 million people and SNAP from 2.4 million by 2034. (Projected — NPR doesn't name the body behind the number.)
Now layer on the incentive. From October 1, 2029, states with eligibility error rates above three percent must repay the federal share above that threshold, and nearly a quarter are already above it. A legitimate program-integrity mechanism; I won't claim Washington built a machine to deny people. But look at the gradient. The penalty attaches to overpayment errors. Nothing matches it for wrongly denying an eligible person.
So imagine you're a state Medicaid director in spring 2028. Your system is the kind a court already found does not consistently load disability status. You've been handed a rule needing fresh employment data every month for millions of people, and a penalty that fires one way only. What do you do? You tune for caution — not out of malice, out of arithmetic. And "caution" in an eligibility engine means the default answer to an unresolved question becomes no.
Now picture what lands in a mailbox in 2029, assuming the address is right. Correct letterhead, correct citation, a reason code reading failed to verify work requirement. Underneath it: a payroll match that missed a second job, an exemption flag nobody set, a household the system reassigned. No line saying this was produced by a rule, and here is the rule. No forum where the rule can be examined. An appeal window measured in days. And a person told, in the calm voice of a machine that can't be cross-examined, that they don't qualify.
Multiply by the roughly 15.5 million people on Medicaid who have a disability, according to KFF — the group whose eligibility depends on exactly the data these systems have been found not to load.
That isn't fantasy. Every component already exists in the record above. I've only added a calendar.
What the people who study this for a living actually say
There is startlingly little ideological daylight on the diagnosis. People disagree fiercely about the direction of the error; almost nobody defends the invisibility of the process.
From the legal academy: Michele E. Gilman of the University of Baltimore, writing in the Harvard Journal of Law & Technology, documents that agencies deploying fraud detection algorithms in welfare programs have wrongfully accused thousands of people of fraud, "with devastating consequences, including bankruptcy, job loss, and psychological trauma," and calls those systems opaque "black boxes" that are "largely unaccountable to the individuals they affect." That work is about fraud detection — adjacent to eligibility, not identical — but "largely unaccountable" is a design property, not an accident, and it travels.
From the right: Paragon and the Foundation for Government Accountability want tighter verification and more data-matching, arguing too many ineligible people are enrolled and the fiscal cost is real. I disagree about where to point the machine — but they aren't arguing in bad faith, and their numbers deserve argument rather than dismissal.
From the center-right on process: the Niskanen Center's treatment of administrative burden concedes what both sides must — that friction in public programs falls hardest on those least equipped to absorb it, whoever wrote the software.
From the advocacy side: NHeLP, EPIC and Upturn took the only federal forum available to them, a consumer-protection complaint, because there's no regulator of benefits algorithms to complain to. And TechTonic Justice's Kevin De Liban, the litigator from Arkansas, has spent a decade arguing this predates the AI conversation.
From the Senate: Ron Wyden's warning that "without stronger oversight and real accountability, these contractors are just going to get a jumbo windfall for creating systems that actually harm Americans trying to get health care" doesn't describe a rule that was broken. It describes a rule that doesn't exist.
Notice what's missing: no American equivalent of the Royal Commissioner, no document in which someone with power to compel testimony writes down what the software did and which law it broke.
What does this mean for you?
If you or someone you love touches a benefits system, here's the practical part. None of it should be necessary. All of it currently is.
Treat every adverse letter as a claim, not a verdict. A denial produced by a bug and one produced by the law are typographically identical. Assume nothing about which you received.
Ask in writing for the specific reason and the data behind it. Not "why was I denied," but "which income figure, from which source, for which period — and what is my recorded disability status?" You're asking the system to show its inputs, and the request is itself a paper trail.
Verify your address of record now, before you need it. A court found enrollees put into wrong households had renewal notices sent to incorrect addresses. The most consequential failure here is a letter you never got about a deadline you then missed.
If your eligibility runs through a disability pathway, confirm the record says so — in writing, with confirmation the flag is set. Michigan and Tennessee both turn on a system not knowing something the person had already told a human.
Appeal, and appeal early. These windows are short and indifferent to why you missed them. A brief, imperfect, on-time appeal beats a beautiful late one.
Get help sooner than feels reasonable — legal aid, a disability rights organization, your state's protection and advocacy agency. A federal judge wrote that benefits shouldn't require "luck, perseverance, or zealous lawyering." Until that's true, get the lawyering.
In an expansion state, get ahead of January 1, 2027. Find out what your state will accept as proof of work, hours or exemption — and what happens in a month you can't produce it.
And if you're not on Medicaid at all: this is still your money and your state's contract. Washington funds 90% of the build; your state signed the deal. Contracts, audits and oversight hearings are public. Ask your legislator who wrote your eligibility rules into code, what it cost, and who audits the output. The answers are almost always obtainable and almost never volunteered.
The lesson, as I see it: make the error visible
Here's the argument I've been building toward — and it's mine, reasoned from the record, not a finding by anybody in it.
The defining danger of eligibility software isn't that it's biased, proprietary or expensive, though it may be all three. It's that when it errs, the error is indistinguishable from a lawful denial.
Look how the pieces fit. In Michigan, the denial rested on a facially lawful ground — too much income — produced by a system that hadn't registered a disability. In Tennessee, a court found the system didn't consistently load disability status. In Arkansas, the remedy for an unexplainable scoring formula was a rewritten notice, not a rewritten formula. The scholarship calls these systems black boxes largely unaccountable to the people they decide about. And an attorney in the middle of it observed that catching the error depends on whichever caseworker happens to look.
Put those together and you get a machine producing two physically identical outputs: a correct denial and a catastrophic mistake. Same paper, same citation, same tone. The appeal system, the oversight system and the political system all key off the content of a decision. None can see its provenance. That's the hole.
Which is why the answer isn't "ban the algorithm" — the alternative to a rules engine isn't a wise human, it's a slower queue. The answer is provenance. Publish the business rules. Make the logic legible to the person it lands on. Require every adverse notice to name the data element and the rule that produced it. Fund an auditor who can read the code. Australia recommended most of that in 2023 and has so far only considered it — and even that is further than we've gotten.
I keep going back to that boolean field. Nobody who writes a default means harm. But a default has to be something, and in a system deciding whether people get medical care, "something" is a policy choice made by someone who thinks it's a technical one. Twenty-five states bought that choice. Most cannot read it. All of us pay for it.
Make the error visible and almost everything else becomes fixable. Leave it invisible, and the most consequential decisions in American social policy will keep being made by a field nobody set, in a file nobody reads, for a reason nobody has to give.
If you know someone who has ever opened an envelope and been told by a machine that they don't qualify — a parent stuck in a renewal, a caseworker drowning in them, a friend who went quiet about it — send this to them specifically. The HAIA Foundation works to keep automated decisions answerable to the people they land on, and this one does more good in their inbox than it ever will in mine.






