Skip to content

PAN Lab example

Medicaid unwinding ex-parte renewals

The unit of determination: an automated renewal system at population scale

A deterministic engine renews coverage automatically by matching records before asking anyone for a form — until one wrong setting, the unit of determination, evaluates every renewal by household instead of by person, and whole families are dropped when any one member cannot be cleared. Modeled on the US Medicaid unwinding ex parte renewal systems — their shape, not any real state system. The engine is accurate; the error is in the specification, so no accuracy dial reaches it. What finally caught it was a federal monitor-and-respond loop — the hopeful counterpoint to a system with no corrective loop at all — but only after mass terminations. The gap the shape turns on is a live individual-level check at the point of determination.

Stylized model of a documented deploymentPublic benefits & eligibility

Open this example in PAN Lab v0.1 to apply pressures and levers and watch what the system does.

What this models

This example runs on the Ex-parte-renewal-class automated eligibility system with a federal monitoring loop network: 7 components and 12 pathways between them. Every context in the Lab is a stylized model, never a reconstruction of any actual deployment, and each assumption behind it carries a provenance label.

Evidence base: 7 assumed · 1 published baseline. In the Lab, the shaded evidence band behind each headline readout draws its width from the least-established class below.

  • assumed

    This models the eligibility-automation error-at-scale pattern documented in the US Medicaid unwinding ex parte renewal case file — not a reconstruction of any actual state system.

  • baseline

    The model-to-model self-loop encodes correlated error at population scale: one deterministic logic applied uniformly to every renewal means a single wrong parameter — the unit of determination — repeats identically across the whole population rather than averaging out, which is why the defect surfaced as roughly 500,000 improper disenrollments across 30 states rather than as scattered noise.

  • assumed

    The engine is drawn as a deterministic data-matching rules engine, not a predictive or machine-learning risk score. The documented failure was a logic and configuration defect — evaluating renewals at the household unit instead of the federally required individual unit — so the error lived in the specification, not in the model's accuracy, and no accuracy metric would have surfaced it.

  • assumed

    The automated procedural-termination path is drawn with a near-silent correction channel (a weak model-to-caseworker route and slow, case-by-case manual corrections), reflecting the documented account that a whole household was dropped procedurally when the form was not returned and that individual override was limited until states reprogrammed their systems and reinstated affected people en masse.

  • assumed

    The federal-monitoring step, run by the Centers for Medicare & Medicaid Services (CMS), is drawn as an oversight loop that worked but was lagged: mandatory monthly reporting and the authority to order suspension of procedural disenrollments caught the defect, but only after mass terminations. Its at-determination reconciliation check starts inactive — the gap the case turns on is not the absence of oversight but the absence of a live individual-level check at the point of determination. This is the deliberate counterpoint to the midas shape, which had no corrective loop at all.

  • assumed

    The household-renewal-form-batch node is drawn as a mediating artifact naming the defect's signature (the whole household batched when any one member cannot be auto-renewed). It carries no flow of its own and does not affect the dynamics.

  • assumed

    The cross-agency-data-matching feed is marked privacy-sensitive because ex parte renewal matches an enrollee's records across wage, tax, Supplemental Nutrition Assistance Program (SNAP), unemployment and Social Security sources. The matching is federally required and protective when correctly implemented; the privacy lever here governs which sensitive sources feed the match, not whether the match runs.

  • assumed

    Harm concentrated on children because their income-eligibility thresholds are far higher than adults', so a child often remained eligible even when a parent did not — an equity-amplifying interaction between the uniform unit defect and a sub-population whose rules diverge. That differential exposure is documented in the case file and recorded outside any diagram like this one; this Lab models institutional propagation, not demographics, and estimates no differential harm to served enrollees.

What this example does not show

  • The documented ~500,000 improper disenrollments across 30 states is an aggregate of state-reported estimates compiled by the Centers for Medicare & Medicaid Services (CMS), not an independently audited count; total-disenrollment figures differ by source and window (KFF recorded ~25.2 million through September 2024; the Government Accountability Office (GAO) found ~27 million in the first 18 months), reflecting different data and methods rather than a contradiction.
  • The documented harm concentrated on children, whose higher income thresholds meant they often stayed eligible when a parent did not. The Lab models institutional workflow propagation, not demographics, and estimates no differential harm to served enrollees; that concentration is documented in the case file and measured outside any diagram like this one. The projection that about 74% of disenrolled children remained eligible is an ASPE estimate, not a post-hoc audit.
  • Two distinct failure modes coexist in the documented record and only the first is modeled here: (a) the household-unit ex parte defect in 30 states, and (b) UNDER-use of ex parte automation in some states, shifting the burden onto error-prone manual paperwork and processing backlogs. Ex parte automation is federally required and protective when correctly implemented; this scenario models the logic defect, not the case against automation.

Sources and evidence

What this example rests on, claim by claim. Every entry resolves to the same ledger the Evidence Registry publishes.

  • A single automated rule set applied uniformly and without human review produced tens of thousands of correlated wrongful fraud determinations in the documented Michigan MiDAS case — one flaw repeating at caseload scale rather than averaging out.

    empirical
    • Government Michigan AG, settlement of civil-rights class action (Bauserman, 2022) https://www.michigan.gov/ag/news/press-releases/2022/10/20/som-settlement-of-civil-rights-class-action-alleging-false-accusations-of-unemployment-fraud
    • Investigative IEEE Spectrum, Michigan's MiDAS unemployment system: Algorithm alchemy that created lead, not gold https://spectrum.ieee.org/michigans-midas-unemployment-system-algorithm-alchemy-that-created-lead-not-gold

Where this connects

Institutional pressures in this domain

  • Austerity & recovery incentives — Cost-cutting and overpayment-recovery targets tilt the system toward denial and enforcement errors.
  • Vendor opacity — The deploying institution cannot inspect the model, data, or update pipeline it is accountable for.
  • Compliance over substance — Paper controls (sign-offs, checklists) satisfy audits while the behavior they describe erodes.
  • Reviewer bottleneck — One fixed-capacity checking stage sits between AI output and consequence; everything queues behind it.

All of them in context on the Public benefits & eligibility domain page.

Levers available here and the patterns behind them

Documented case histories