You know what I saw last Friday?
I saw a press conference that was actually a campaign stop. U.S. Sen. Tom Cotton rolled into town, and Gov. Sarah Huckabee Sanders and Attorney General Tim Griffin played supporting actors in his show. They called it a news conference to announce Cotton co-sponsoring S.4176, a bill that would expand the authority of state Medicaid Fraud Control Units (MFCUs) to investigate and prosecute people applying for or receiving Medicaid for fraud. MFCUs are housed in the state attorney general’s office and currently only have authority to investigate and prosecute Medicaid fraud by providers. I call it what it was: theater instead of governance.
Arkansas uses an automatic eligibility system for Medicaid, and its failures and flaws are well-documented.
The state contracted with Deloitte to provide the eligibility system, the same Deloitte that was the subject of a 2024 Federal Trade Commission complaint for its “development and maintenance of a faulty” Medicaid eligibility system for Texas. Litigation in Tennessee alleges newborns were losing coverage because Deloitte’s eligibility system failed to link them with their mothers, and the system also improperly merged households. In Florida, the Deloitte-built system erroneously cut benefits for new and expecting mothers. And in Kentucky, a problem with their prevented coverage applications from getting through online. It was an error that cost $522,455 and took 10 months to resolve.
And Arkansas? In 2025, I discovered the Deloitte system erroneously merged me into my ex-wife’s household at an address where I never lived. I was unaware of this error for months, and it was the reason I was denied coverage on the health insurance marketplace. I reported it and demanded a legislative hearing. I was told the attorney general was the only one who could investigate Deloitte. I have the FOIAs and receipts to prove it.
You can’t get anyone at the Capitol to even say the word Deloitte.
Instead of demanding answers for system failures, the state keeps rewarding the company with more contracts. Arkansas has awarded Deloitte more than $515 million across five DHS technology and information services contracts, including the state’s Medicaid eligibility technology, cloud support, DHS enhancement work, statewide information-support services and ARIES maintenance and operations, according to the state transparency website.
Let’s connect some dots.
Ben Gilmore, a former state senator from Crossett who was co-chair of the Arkansas Legislative Council, which reviews state agency contracts like Deloitte’s, just resigned his seat to become a senior advisor for Griffin. He joined Griffin’s office on July 1.
Ben’s brother, Jon Gilmore, is the owner of the Gilmore Davis Barker Group, a lobbying and campaign strategy firm. And guess who one of his clients is? Deloitte.
So the man Arkansans are told is the only one who can investigate Deloitte just hired, as a senior advisor, the former legislator who oversaw Deloitte’s contract and whose own brother lobbies for Deloitte.
On June 24, 2024, KFF Health News published a national investigation exposing critical flaws in Deloitte’s Medicaid eligibility systems, including failures in Arkansas. The next day, Deloitte’s PAC cut checks for $500 to $1,000 each to eight Arkansas legislators, including the House speaker, the Senate president pro tempore, the House majority leader, and the co-chair and members of the committee that reviews Deloitte’s contracts. Ben Gilmore got $1,000, according to quarterly reports filed by Deloitte PAC.
I said it then and I’ll say it now: the system is broken. It protects the powerful and locks out everyone else.
Arkansas is paying Deloitte $500 million in technology contracts, including for a broken eligibility system the attorney general won’t investigate, while he wants to go after the fraud committed by individual applicants or beneficiaries. The state has identified only dozens of beneficiary-fraud referrals in the OMIG reports we’ve reviewed, yet the proposed expansion comes without publicly quantifying how many cases are falling through the existing system or how much money is actually at stake.
Griffin’s office is supposed to protect consumers. Instead of going after the company that’s kicking newborns off their health coverage, he wants to go after healthcare consumers who are more likely to be harmed by Deloitte than commit large-scale fraud.
It is asinine to cover this press conference without peeling back this insult to the public’s intelligence.
DHS already investigates Medicaid fraud through its Office of Security and Compliance. They also investigate beneficiary fraud for other benefit programs such as SNAP and TEA, a lane Griffin expressed interest in at the press conference. They already forward cases to prosecutors if it rises to the level of criminal charges. They also refer cases to other departments in DHS for administrative disqualification and to seek repayment of benefits.
The only additional enforcement avenue that expanding MFCU authority to beneficiaries creates is that it allows Griffin to sue these people in civil court. He will have to forward cases to prosecutors to pursue criminal charges. He won’t be able to remove anyone from the program – DHS will have to do that.
Are the individual fraud amounts enough to warrant the cost of civil litigation? The threshold for DHS to initiate fraud investigations is $200. Under DHS regulations, a case won’t be referred for criminal prosecution if “the total amount of the overpayment resulting from the alleged fraud is less than five hundred dollars ($500).” The same regulation already builds in exactly the fallback Griffin says the state needs: cases screened out for prosecution by overpayment thresholds, or for age, statute of limitations, or the suspect living out of state, “may be referred for an administrative disqualification hearing” instead, decided case-by-case by the DHS fraud investigation unit director, according to agency rules.
The problem Griffin identified may be a gap in MFCU authority, but that does not establish a gap in the state’s ability to investigate, administratively adjudicate, recover or otherwise address beneficiary fraud.
Expanding MFCU authority to beneficiary fraud would be duplicative.
We’re deep-diving into Medicaid Fraud Control Unit, Office of the Medicaid Inspector General (which also investigates providers for fraud) and the DHS Fraud Investigation Unit expenses and case analytics. We’ve FOIA’d the records and will report when we review them.
Here’s how Griffin put it in his own press release announcing the push: “Every dollar lost to fraud is a dollar that cannot be used to provide care and services for Arkansans who genuinely need and qualify for assistance.” He said the goal is “ensuring that public benefits remain available for those who qualify for and depend upon them.”
Ask the new mothers in Florida who lost coverage because of a Deloitte system error whether that’s what happened to them. Ask me.
Sanders put it this way: “Medicaid should be a safety net for Arkansans who need it, not a slush fund for criminals looking to game the system.” Arkansas is sending Deloitte half a billion dollars in contracts that include a system with a documented, multi-state track record of wrongly cutting people off that safety net, and nobody at that podium has called for an investigation into Deloitte.
Cotton called it “cracking down on fraud” and said the bill will help “root out Medicaid fraud once and for all.” Fine. Start with the biggest number on the page.
When asked by Arkansas Democrat-Gazette reporter Michael Wickline at the presser how many cases he hasn’t been able to prosecute because of the existing law, Griffin said:
“There’s no way of knowing — it’s just an obvious hole in MFCU authority. It’s common sense this occurs. ... Not every case will lend itself to prosecution, but we need options.”
There was already data Griffin could refer to for a starting point. In FY2022, the Office of the Medicaid Inspector General (OMIG) referred 53 cases of suspected Medicaid beneficiary fraud to DHS, according to its 2022 annual report. In FY23, OMIG referred 24 cases, according to the 2023 report. This information was not included in the 2024 report, so it’s unclear if there were no referrals or if OMIG elected not to report them. We’ve asked OMIG for the information and are awaiting a response.
DHS was at the press conference, so was Allison Bragg, the Medicaid Inspector General. Wickline’s question could have been answered by the bureaucrats sitting right there in that room.
Not one news outlet who covered the announcement mentioned the DHS fraud investigation unit. They took the framing that this is a needed expansion of state AG power and ran with it.
The story no one else is reporting is another fine example of comms before compliance. Press release before substance. A plausible cover story that sounds good, but doesn’t hold up once you know the full context.
If Arkansas already has a system for identifying, investigating, administratively resolving, recovering and referring beneficiary fraud, and OMIG already has data showing beneficiary-fraud referrals, what specific problem does S.4176 solve, how many cases are currently falling through the gap, how much money is involved, and what will the new enforcement authority cost taxpayers?
Those are questions the press conference should have answered. Instead, we got the same old media circus, performed by three clowns on the 12th floor of Griffin’s ivory tower.

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.