States that run Medicaid waivers for home and community-based services must promise CMS they have safeguards to protect people's health and welfare, and CMS can refuse or end a waiver if they don't. Those promises, called state assurances, are set out at 42 CFR 441.302, and, as of September 2026, the 2024 federal Access Rule requires states to meet a detailed incident management standard starting July 9, 2027.

Oversight of services for people with intellectual and developmental disabilities is shared by many hands: the state Medicaid and disability agencies, licensing and survey staff, investigators, fraud units and federal auditors. This brief explains who checks what, how critical incidents are handled and what happens when problems are found at a provider agency.

Who oversees what

WhoWhat they checkMain federal rule
State Medicaid and developmental disabilities agenciesProvider standards, licensing, service plans, incident systems for HCBS42 CFR 441.302
State survey agencyICF/IID certification surveys42 CFR 442.109; 42 CFR 483, Subpart I
Medicaid Fraud Control UnitMedicaid fraud, and abuse or neglect in facilities42 CFR 1007.11
State Medicaid agency, program integrityPayment suspensions on credible allegations of fraud42 CFR 455.23
CMSWaiver approval and state reports42 CFR 441.302 and 441.311
HHS Office of Inspector GeneralAudits and investigations of federal health programsVaries

What states promise CMS for HCBS

Under 441.302(a), a state's health and welfare safeguards must include:

  • Provider standards. Adequate standards for every type of provider under the waiver.
  • Licensing. Assurance that state licensure or certification standards are met.
  • Settings. Services delivered in settings that meet the HCBS settings rule. See HCBS settings rule: what 42 CFR 441.301(c)(4) requires.
  • Incident management. A system that identifies, reports, triages, investigates, resolves, tracks and trends critical incidents.

States must also assure financial accountability, including an independent audit of the waiver program (441.302(b)).

Critical incidents under the 2024 rule

The 2024 rule spells out what the incident management system must do. At a minimum, a state must define a critical incident to include:

  1. Verbal, physical, sexual, psychological or emotional abuse.
  2. Neglect.
  3. Exploitation, including financial exploitation.
  4. Misuse or unauthorized use of restrictive interventions or seclusion.
  5. A medication error that leads to a call to poison control, an emergency room or urgent care visit, a hospitalization or death.
  6. An unexplained or unanticipated death, including one caused by abuse or neglect.

States must also:

  • Require providers to report critical incidents to the state within state-set timeframes, whether the incident happened during services or because services in the person-centered service plan weren't delivered.
  • Look for unreported incidents using claims data, Medicaid Fraud Control Unit data and data from agencies such as Adult Protective Services, where state law allows.
  • Share information on the status of investigations with other agencies that investigate, and investigate on their own if those agencies don't report results on time.
  • Meet performance targets. For at least 90% of critical incidents, states must start an investigation, complete it and, where needed, finish corrective action within state-set timeframes.

States must report their results to CMS: an assessment of the system every 24 months and incident data every year (42 CFR 441.311(b)). These requirements apply from July 9, 2027, and a separate requirement for an electronic system to collect, track and trend incident data applies from July 9, 2029. Community First Choice programs must meet the same incident standard (42 CFR 441.570(e)). A CMS proposed rule now under federal review could revise parts of the 2024 rule.

How ICF/IID oversight works

ICFs/IID are certified facilities with their own federal conditions of participation. Oversight includes:

  • Regular surveys. The state survey agency must survey each ICF/IID no later than 15 months after its last survey, and the statewide average interval must be 12 months or less (42 CFR 442.109).
  • Immediate reporting. Facilities must report all allegations of mistreatment, neglect or abuse, and injuries of unknown source, immediately to the administrator or other officials under state law (42 CFR 483.420(d)(2)).
  • Investigation. Facilities must thoroughly investigate, prevent further potential abuse while the investigation is under way and report results within five working days of the incident. If a violation is verified, corrective action must follow (483.420(d)(3)-(4)).
  • Staff screening. Facilities must not employ people with a conviction or prior employment history of child or client abuse, neglect or mistreatment (483.420(d)(1)(iii)).

For how ICFs/IID differ from HCBS, see HCBS vs. ICF/IID.

Fraud units and payment suspensions

A state's Medicaid Fraud Control Unit runs a statewide program to investigate and prosecute Medicaid fraud. The unit also reviews complaints of abuse or neglect of residents in health care facilities that receive Medicaid, and may review complaints from board and care facilities (42 CFR 1007.11).

When a state Medicaid agency finds a credible allegation of fraud under investigation, it must suspend Medicaid payments to that provider unless it finds good cause not to or to suspend only in part (42 CFR 455.23). It may suspend without warning, must send notice within five days in most cases and must refer the case in writing to the fraud unit by the next business day. Suspensions are temporary and end when the evidence is found insufficient or legal proceedings finish.

Audits and state enforcement

Federal auditors also check providers directly. In a June 2026 audit of North Dakota residential providers for people with I/DD, the HHS Office of Inspector General found 182 instances of provider noncompliance with administrative, health, safety and residential records requirements; see our coverage of the North Dakota audit. States add their own tools. New Jersey, for example, can fine I/DD providers for serious violations starting July 1, 2026; see our New Jersey coverage.

Why this matters for providers and DSPs

  • Reporting starts with the person on shift. Most incident systems depend on the first report from a DSP or house staff member. Knowing what counts as a critical incident, and your state's timeframe, is part of the job.
  • Missed services can be incidents too. Under the 2024 rule, an incident that happens because authorized services weren't delivered must be reported, not just events during a shift. Short staffing can create reportable events.
  • Unreported incidents can surface anyway. States must use claims, fraud unit and protective services data, where state law allows, to find incidents providers didn't report. An incident that wasn't reported but later appears in those records is a serious compliance problem.
  • Documentation is evidence. Clear, timely notes support investigations, show corrective action was completed and back up the claims that pay for services. Notes that are late, vague or copied from shift to shift can weaken an investigation and the claim behind it.
  • Supervisors close the loop. Corrective action has to be completed on time for at least 90% of incidents that need it. Frontline supervisors often carry out and document those steps.