Health plan FDR compliance is the compliance program a vendor or delegated organization runs to meet the contract and oversight requirements of the health plans it serves; in Medicare Advantage, a first tier entity is a party with a written arrangement with the plan "to provide administrative services or health care services for a Medicare eligible individual" (42 CFR 422.2). This page is for smaller service vendors and delegated organizations that contract with health plans and must show those plans a working compliance program. Integral Healthcare Solutions (IHS) builds your contract requirement register and drafts the compliance procedures and audit evidence a health plan reviews; your counsel approves interpretations.
Last reviewed: October 2026.
What is FDR compliance?
FDR compliance has two layers of governing text. The first is your own contract with each health plan and that plan's FDR oversight requirements. The second, where you serve Medicare Advantage members, is the Medicare Advantage regulation at 42 CFR Part 422: the definitions in section 422.2, the plan compliance program in section 422.503(b)(4)(vi) and the FDR relationship in section 422.504(i). This page quotes the eCFR text current as of 30 September 2026.
The definitions set who is in scope. A first tier entity "enters into a written arrangement, acceptable to CMS, with an MA organization or applicant to provide administrative services or health care services for a Medicare eligible individual under the MA program." A downstream entity "enters into a written arrangement, acceptable to CMS, with persons or entities involved with the MA benefit, below the level of the arrangement between an MA organization (or applicant) and a first tier entity" (42 CFR 422.2).
The plan keeps the responsibility: "the MA organization maintains ultimate responsibility for adhering to and otherwise fully complying with all terms and conditions of its contract with CMS" (42 CFR 422.504(i)(1)). That is why plans push requirements down to vendors. Their compliance program must include "an effective system for routine monitoring and identification of compliance risks" that evaluates "first tier entities', compliance with CMS requirements," and lines of communication between the compliance officer and "the MA organization's first tier, downstream, and related entities" (42 CFR 422.503(b)(4)(vi)(F) and (D)).
The plan layer is where most day-to-day obligations sit. One plan's published list, from BlueCross BlueShield of Tennessee, reads: "Implement fraud, waste and abuse (FWA) and general compliance training."; "Screen for excluded individuals and entities."; "Distribute the Code of Conduct/compliance program policy."; "Report FWA and general compliance concerns to us."; "Maintain record retention."; "Report offshore subcontracting."; "Monitor and audit downstream and related entities." (BCBST FDR oversight). That is one plan's list. Your obligations are the ones in your own contracts and each plan's oversight manual.
This page quotes Part 422 only, not the Part D rules in 42 CFR Part 423; if you serve Part D sponsors, that text is read when the engagement is scoped.
Who needs it and what triggers it
A vendor needs an FDR compliance program when a health plan contract makes it one, and the plan's oversight requirements then set the program's content. The usual triggers are:
- A new or renewed health plan contract that carries FDR oversight requirements, such as the training, screening, reporting and record-retention items on the BCBST list.
- A plan's monitoring or audit of your compliance. The plan's compliance program must routinely monitor first tier entities' compliance with CMS requirements (42 CFR 422.503(b)(4)(vi)(F)).
- A records request under the audit right your contract must contain: "HHS, the Comptroller General, or their designees have the right to audit, evaluate, collect, and inspect any books, contracts, computer or other electronic systems, including medical records and documentation" of first tier, downstream and related entities (42 CFR 422.504(i)(2)(i)).
- Adding your own subcontractors. Once you subcontract MA work, those parties can be downstream entities, and plans such as BCBST require you to "Monitor and audit downstream and related entities."
- Moving work offshore, which the BCBST list requires you to report.
Whether your company is a first tier or downstream entity turns on your written arrangements read against the 422.2 definitions. IHS's reading of those definitions (October 2026) is that any vendor providing administrative or health care services for a plan's Medicare members under a written arrangement should expect to be treated as one. Your counsel confirms the status for each contract.
How IHS helps
IHS builds your program from your contracts outward. The process:
- Requirement register. IHS reads each health plan contract and oversight manual you hold and lists every compliance obligation, plan by plan, in one contract requirement register. This is the gap assessment's yardstick.
- Gap assessment. Each obligation in the register is checked against your current policies, training records, screening logs and reporting practice.
- Document and evidence mapping. Each obligation is crosswalked to the policy that meets it and the record that proves it, so one document can answer several plans.
- Drafting. IHS drafts the compliance policies, the training and exclusion-screening procedures, incident and concern reporting procedures, and the audit evidence files a plan asks for. Your compliance officer and functional owners review and approve them.
- Mock plan audit. IHS runs a mock audit of your files against the register.
- Readiness support. When a plan audit returns findings, IHS drafts the responses for your organization to send to the plan.
What you supply: your health plan contracts and oversight manuals, current policies, training and screening records, and the functional owners for each obligation.
The limit: contract interpretation belongs to your counsel, and the register is built contract by contract, so a new plan contract means a new pass through the register. IHS does not decide whether you are an FDR under a given contract, and it does not speak for you to the plan or to CMS.
What to have ready
Each item ties to 42 CFR Part 422 (eCFR current as of 30 September 2026) or to the BCBST FDR oversight page as one plan's example. Substitute each of your plans' own requirements where they differ.
- Every current health plan contract and amendment, including the clause granting HHS and the Comptroller General the right "to audit, evaluate, collect, and inspect any books, contracts, computer or other electronic systems" (42 CFR 422.504(i)(2)(i)).
- Each plan's FDR oversight manual or requirements page, such as the BCBST FDR oversight page.
- A list of the services you provide for Medicare members under each contract, to test against the first tier and downstream definitions (42 CFR 422.2).
- Training records for fraud, waste and abuse and general compliance training ("Implement fraud, waste and abuse (FWA) and general compliance training," BCBST).
- Exclusion screening logs for staff and entities ("Screen for excluded individuals and entities," BCBST).
- Your code of conduct or compliance program policy and proof it was distributed ("Distribute the Code of Conduct/compliance program policy," BCBST).
- The channel and log you use to report concerns to each plan ("Report FWA and general compliance concerns to us," BCBST), and the name of the person the plan's compliance officer communicates with (42 CFR 422.503(b)(4)(vi)(D)).
- Your record retention schedule ("Maintain record retention," BCBST).
- A list of any offshore subcontractors ("Report offshore subcontracting," BCBST).
- A list of your own downstream and related entities and the records of how you monitor them ("Monitor and audit downstream and related entities," BCBST).
The introductory call is the place to go through this list against your current files.
How it compares
A vendor can organize plan compliance in two ways. The difference is how the requirements are kept, not what they are.
- Plan by plan. The vendor builds or adjusts its program to each plan's oversight manual as each contract or audit arrives. The requirements stay tied to the plan that set them, and each plan's manual remains the reference for that plan.
- One program mapped to every contract. The vendor keeps one set of policies and records and a register that crosswalks each plan's requirements to them. One policy can answer several plans, and the register shows where a plan asks for more than the others.
Either path still has to meet the plan's requirements as written in each contract; the 42 CFR 422.504(i)(1) responsibility stays with the plan in both.
What it costs
IHS found no application or accreditation fee for FDR status on the pages reviewed. FDR requirements come from your plan contracts and, in Medicare Advantage, 42 CFR Part 422. The cost is the staff time to build and keep the program, plus any outside help. IHS scopes each engagement after a free introductory call.
What this is not
- It is not legal advice. Your counsel interprets your contracts and decides whether you are a first tier, downstream or related entity.
- It is not a guarantee of a plan audit result. The plan decides whether your program meets its requirements.
- IHS does not correspond with CMS or the plan for you. IHS drafts; your organization sends.
Frequently asked questions
What is a first tier, downstream or related entity (FDR) in Medicare Advantage?
A first tier entity is a party with a written arrangement, acceptable to CMS, with an MA organization "to provide administrative services or health care services for a Medicare eligible individual under the MA program." A downstream entity holds a written arrangement below the level of the arrangement between the plan and a first tier entity (42 CFR 422.2). FDR is the shorthand for first tier, downstream and related entities.
Is my company an FDR if we provide services to a health plan's Medicare members?
Probably, if you do it under a written arrangement with the plan or with one of its first tier entities. That is IHS's reading of the 42 CFR 422.2 definitions as of October 2026. Your counsel confirms the status contract by contract.
What compliance program elements do health plans require from FDR vendors?
Each plan sets its own list in its contract and oversight manual. One published example, from BlueCross BlueShield of Tennessee, covers FWA and general compliance training, exclusion screening, distributing a code of conduct, reporting concerns to the plan, record retention, reporting offshore subcontracting, and monitoring and auditing downstream and related entities (BCBST).
Do FDRs have to screen employees against exclusion lists, and how often?
BlueCross BlueShield of Tennessee requires it: its list says "Screen for excluded individuals and entities" (BCBST). Other plans' requirements are set in each plan's contract and oversight manual. The frequency and the lists to check are not stated in the passage quoted here. IHS drafts a screening procedure that meets the strictest requirement across your plans.
What compliance and FWA training does a health plan expect its vendors to complete?
The BCBST list requires vendors to "Implement fraud, waste and abuse (FWA) and general compliance training" (BCBST). The content, audience and timing come from each plan's own requirements. IHS drafts the training procedure and the records that show completion.
Can CMS audit a vendor directly, not just the health plan?
Yes, through the contract. FDRs must agree that "HHS, the Comptroller General, or their designees have the right to audit, evaluate, collect, and inspect any books, contracts, computer or other electronic systems, including medical records and documentation" of first tier, downstream and related entities (42 CFR 422.504(i)(2)(i)).
How do we handle offshore subcontracting disclosure to a health plan?
Report it the way each plan's contract requires. The BCBST list states "Report offshore subcontracting" (BCBST). IHS adds offshore work to your requirement register so each plan's reporting duty is tracked.
How do we respond to a corrective action plan from a health plan audit?
Your organization answers the plan under the plan's process. IHS drafts the response, the corrective steps and the evidence that each step is done, for your organization to review and send.
How do we manage different compliance requirements across several health plan contracts?
Build one contract requirement register that lists every obligation by plan, then crosswalk each obligation to the policy and record that meets it. A new contract adds rows to the register rather than a new program.
