See the stars

MedIQ Specification

Home / MedIQ / MedIQ Specification

MedIQ

Transforming Medicaid to Medicare with Intelligence


MedIQ is an open-source specification for an intelligent, secure, auditable platform designed to automate legally authorized Medicaid-to-Medicare transition workflows. MedIQ coordinates identity verification, eligibility assessment, benefit reconciliation, state and federal data integration, anomaly detection, investigative review, reporting, budgeting, and citizen communications through a modular architecture.

MedIQ is designed to operate across states while accommodating differences in state Medicaid programs, federal Medicare requirements, authorized data sources, eligibility rules, operational procedures, and regulatory requirements.

The system is designed to automate administrative workflows while preserving required human oversight, statutory decision-making authority, due process, appeals, civil-rights protections, and legally required review.

Design Principles

  • Open source and vendor-neutral
  • Modular and extensible architecture
  • State-by-state adaptability
  • Federated data architecture
  • Privacy-preserving data handling
  • End-to-end security
  • Deterministic eligibility and policy rules
  • AI-assisted analysis rather than unsupported automated adverse decisions
  • Full provenance and auditability
  • Human oversight for consequential determinations
  • Explainable decisions and recommendations
  • Data minimization
  • Interoperability through governed APIs and connectors
  • Continuous regulatory and policy versioning
  • Accessible citizen services
  • Transparent public reporting where legally permitted
  • Simulation without exposure of production data
  • Separation of identity, eligibility, analytics, and administrative functions

Core Modules

Identity and Eligibility Verification

MedIQ shall provide a comprehensive identity and eligibility verification framework capable of validating information required for legally authorized Medicaid and Medicare workflows.

Capabilities include:

  • Identity proofing and verification
  • KYC-aligned identity verification workflows where legally appropriate
  • EVVE integration through authorized interfaces
  • Real ID document verification where applicable
  • Government identification document validation
  • Government ID OCR
  • Social Security number validation
  • Birth record validation
  • Citizenship verification where required by the applicable program
  • Residency verification where required
  • Date-of-birth verification
  • Duplicate identity detection
  • Identity conflict detection
  • Identity re-verification
  • Suspected identity theft workflows
  • Automated verification status tracking
  • Two-factor authentication and multifactor authentication
  • Consent and authorization tracking
  • Identity evidence provenance
  • Verification confidence reporting
  • Manual verification workflows for unresolved cases

MedIQ shall not treat citizenship alone as sufficient to establish Medicare eligibility. Eligibility shall be determined according to the applicable federal program requirements and the individual’s circumstances.

Medicaid-to-Medicare Transition Automation

MedIQ shall provide an automated workflow engine for identifying individuals who may qualify for a Medicare transition or coordination process.

Capabilities include:

  • Medicaid enrollment analysis
  • Medicare eligibility assessment
  • Medicare Part A assessment
  • Medicare Part B assessment
  • Medicare Advantage coordination
  • Medicare Part D coordination
  • Medicare Savings Program assessment
  • Dual-eligibility assessment
  • Disability-related Medicare eligibility workflows
  • Age-related Medicare eligibility workflows
  • ESRD and other applicable Medicare eligibility pathways
  • Coverage overlap analysis
  • Transition event detection
  • Automated case creation
  • Eligibility evidence collection
  • Missing-information detection
  • Coverage effective-date coordination
  • Enrollment workflow scheduling
  • Transition status tracking
  • State-specific workflow rules
  • Federal program rules
  • Policy-version tracking
  • Exception handling
  • Human review routing when required
  • Appeal and reconsideration workflows
  • Citizen notification workflows

The transition engine shall distinguish between automated administrative processing and determinations that require authorized governmental decision-makers.

Deterministic Rules and Policy Engine

MedIQ shall provide a version-controlled rules engine for implementing federal and state eligibility requirements.

Capabilities include:

  • Federal eligibility rules
  • State Medicaid rules
  • Medicare eligibility rules
  • Medicare Savings Program rules
  • State-specific program rules
  • Effective-date management
  • Rule versioning
  • Historical rule reconstruction
  • Policy change tracking
  • Deterministic calculations
  • Eligibility evidence mapping
  • Rule execution provenance
  • Rule conflict detection
  • Regulatory requirement mapping
  • Human-review thresholds
  • Jurisdiction-specific policy configuration

Every eligibility result shall identify the rules, evidence, policy version, and processing conditions used to produce the result.

Federated Data Model

MedIQ shall use a federated data model that allows participating jurisdictions and authorized organizations to maintain control over their data while enabling governed interoperability.

Capabilities include:

  • Federated identity references
  • Federated eligibility records
  • Federated Medicaid service histories
  • Federated Medicare records
  • Cross-jurisdiction data reconciliation
  • Data lineage
  • Source attribution
  • Evidence provenance
  • Data freshness tracking
  • Consent-aware access
  • Purpose-based access controls
  • Data minimization
  • Cross-state coordination
  • Duplicate record detection
  • Conflict resolution
  • Historical record preservation
  • Data synchronization controls
  • Federated query capabilities where legally authorized

MedIQ shall avoid unnecessary centralization of sensitive information.

Medicaid and Medicare Service History

MedIQ shall provide historical service record reconciliation to support transition processing, anomaly analysis, audits, and authorized reporting.

Capabilities include:

  • Medicaid service history retrieval
  • Medicare service history retrieval
  • Claims history reconciliation
  • Provider relationship analysis
  • Coverage period analysis
  • Duplicate service detection
  • Overlapping benefit analysis
  • Historical eligibility reconstruction
  • Service utilization trends
  • Longitudinal beneficiary records
  • Evidence provenance
  • Record discrepancy identification
  • Historical data integrity verification

Access to historical information shall be limited according to applicable authorization, privacy, retention, and disclosure requirements.

Fraud, Waste, Abuse, and Anomaly Detection

MedIQ shall provide analytics for identifying potential anomalies, inconsistencies, waste, fraud, abuse, duplicate benefits, and other risk indicators.

Capabilities include:

  • Pattern recognition
  • Statistical anomaly detection
  • Cross-state anomaly detection
  • Duplicate claim detection
  • Duplicate benefit detection
  • Identity anomaly detection
  • Coverage overlap analysis
  • Unusual utilization analysis
  • Provider pattern analysis
  • High-risk event alerts
  • Risk scoring
  • Risk-factor explanation
  • Historical comparison
  • Investigation prioritization
  • Authorized external fraud-data integration
  • Case escalation
  • Evidence preservation

Risk scores and anomaly indicators shall not independently determine adverse eligibility, enrollment, or benefit outcomes.

Investigative Audit Generation

When a qualifying anomaly is detected, MedIQ shall generate a structured investigative audit package.

Capabilities include:

  • Anomaly summary
  • Trigger identification
  • Evidence inventory
  • Historical service analysis
  • Eligibility history
  • Identity verification history
  • Relevant transactions
  • Related records
  • Cross-jurisdiction comparisons
  • Rule and policy references
  • Risk indicators
  • Data provenance
  • Timeline reconstruction
  • Investigator notes
  • Recommended review actions
  • Human-review status
  • Resolution tracking
  • Audit history
  • Tamper-evident records

Investigative reports shall distinguish verified facts, system-generated observations, risk indicators, unresolved questions, and human conclusions.

AI Analytics and Explainability

MedIQ shall provide AI-assisted analytics for identifying patterns, prioritizing reviews, analyzing historical data, and generating structured reports.

Capabilities include:

  • AI anomaly detection
  • Predictive risk analysis
  • Historical trend analysis
  • Pattern discovery
  • Automated audit-report generation
  • Anomaly classification
  • Predictive policy analysis
  • Resource optimization
  • Statistical forecasting
  • Explainable AI outputs
  • Confidence indicators
  • Evidence-linked explanations
  • Model performance monitoring
  • Model version tracking
  • Bias and disparate-impact monitoring
  • Human review workflows
  • Model feedback loops
  • Federated learning capabilities where legally and technically appropriate

AI-generated recommendations shall remain distinguishable from deterministic eligibility rules and authorized human decisions.

Historical Data Analysis

MedIQ shall provide a dedicated historical analysis capability for identifying long-term trends, inefficiencies, systemic patterns, and changes across jurisdictions.

Capabilities include:

  • Multi-year trend analysis
  • State-by-state comparisons
  • Enrollment trends
  • Transition trends
  • Utilization trends
  • Cost trends
  • Fraud and anomaly trends
  • Program efficiency analysis
  • Administrative workload analysis
  • Policy impact analysis
  • Systemic issue detection
  • Historical anomaly analysis
  • Population-level reporting using appropriate privacy protections

Reporting and Audit

MedIQ shall provide comprehensive reporting for citizens, administrators, states, federal agencies, auditors, investigators, and other authorized users.

Capabilities include:

  • Citizen-level reports
  • State-level reports
  • Federal reports
  • CMS-oriented reporting
  • Medicaid program reports
  • Medicare transition reports
  • Eligibility reports
  • Identity verification reports
  • Fraud and anomaly reports
  • Investigative audit reports
  • Budget reports
  • Historical analysis reports
  • Explainable AI reports for auditors
  • Data provenance reports
  • Compliance reports
  • Exportable audit trails
  • CSV export
  • PDF export
  • Report versioning
  • Report integrity verification
  • Scheduled reporting
  • Custom report generation

Budget Integration and Financial Analysis

MedIQ shall provide budgeting and financial analysis capabilities for authorized state and federal users.

Capabilities include:

  • Medicaid budget integration
  • Medicare transition cost analysis
  • Enrollment cost forecasting
  • Multi-year forecasting
  • Real-time expense monitoring where data access permits
  • Budget variance analysis
  • Budget overage alerts
  • Anomaly-based financial alerts
  • Program cost analysis
  • State-level cost comparison
  • Federal cost analysis
  • Resource forecasting
  • Administrative cost analysis
  • Scenario-based financial modeling
  • Historical expenditure analysis

Budget analytics shall distinguish projections from verified financial records.

Simulation Mode

MedIQ shall provide a Simulation Mode that allows authorized users to model program, financial, operational, fraud, and coverage scenarios without modifying production records.

Capabilities include:

  • Synthetic beneficiary scenarios
  • Synthetic claims scenarios
  • Policy simulations
  • Enrollment simulations
  • Transition simulations
  • Fraud-prevention simulations
  • Budget simulations
  • Coverage simulations
  • Workforce simulations
  • State policy comparison
  • Multi-year projections
  • Impact analysis
  • What-if analysis
  • Model validation
  • AI evaluation
  • Rule testing
  • Anonymized or synthetic datasets

Simulation results shall be clearly separated from production decisions and production records.

Citizen Portal and User Experience

MedIQ shall provide a public-facing citizen portal for authorized users.

Capabilities include:

  • Secure account access
  • Identity verification
  • Multifactor authentication
  • Transition status
  • Eligibility information
  • Required documentation
  • Coverage information
  • Medicare program information
  • Personalized notifications
  • Secure document submission
  • Consent management
  • Communication preferences
  • Application status
  • Review status
  • Appeal status
  • Accessible explanations
  • AI-assisted guidance
  • Human support escalation
  • Multilingual support
  • Mobile-responsive access
  • Accessibility support

Citizen-facing information shall clearly distinguish system guidance from official eligibility determinations.

Administrative Dashboards

MedIQ shall provide role-specific dashboards for authorized state, federal, administrative, investigative, and audit personnel.

Capabilities include:

  • Case management
  • Transition queues
  • Eligibility status
  • Verification status
  • Anomaly alerts
  • Investigation queues
  • Budget dashboards
  • Historical analytics
  • State comparisons
  • Workforce workload
  • Review scheduling
  • Appeals management
  • Audit management
  • System health
  • Data quality
  • API health
  • Security alerts
  • Model monitoring

Appeals and Human Review

MedIQ shall provide workflows for required human review, reconsideration, appeals, exceptions, and adverse-action safeguards.

Capabilities include:

  • Human review queues
  • Automated routing
  • Review prioritization
  • Evidence packages
  • Decision documentation
  • Reconsideration workflows
  • Appeal workflows
  • Deadlines and notifications
  • Case escalation
  • Reviewer notes
  • Decision provenance
  • Citizen notification
  • Due-process tracking
  • Review outcome analytics

No automated system output shall eliminate a legally required right to human review, appeal, reconsideration, notice, or due process.

API and Integration Framework

MedIQ shall provide a governed integration framework capable of connecting to authorized state, federal, healthcare, identity, financial, and benefits systems.

Capabilities include:

  • State API connectors
  • Federal API connectors
  • Eligibility data connectors
  • Identity verification connectors
  • EVVE connectors
  • Authorized Real ID verification interfaces
  • Medicaid data connectors
  • Medicare data connectors
  • Claims data connectors
  • Provider data connectors
  • Fraud and abuse data connectors
  • Budget data connectors
  • Notification services
  • Document services
  • Webhook processing
  • Event-driven integrations
  • API version management
  • Rate limiting
  • Authentication
  • Authorization
  • Integration monitoring
  • Connector health monitoring
  • Data transformation
  • Schema validation
  • Error handling
  • Retry management
  • Integration audit trails

MedIQ shall treat external systems as governed integrations and shall not assume that an API exists or is available without authorization.

Security and Privacy

MedIQ shall implement comprehensive security and privacy controls appropriate for sensitive government and healthcare-related information.

Capabilities include:

  • End-to-end encryption
  • Encryption at rest
  • Encryption in transit
  • Strong cryptographic controls
  • Support for validated cryptographic modules where required
  • TLS 1.3 support
  • Zero Trust security principles
  • Role-based access control
  • Attribute-based access control where appropriate
  • Least-privilege authorization
  • Multifactor authentication
  • Session expiration
  • Device and session monitoring
  • Privileged-access management
  • Secure key management
  • Hardware-backed key protection where appropriate
  • Tamper-evident audit logs
  • Security event monitoring
  • Threat detection
  • Automated incident response
  • Data anonymization
  • Data minimization
  • Purpose limitation
  • Retention controls
  • Secure deletion
  • Break-glass access controls
  • Access review
  • Security testing
  • Vulnerability management
  • Disaster recovery
  • Business continuity
  • Backup integrity verification

The implementation shall support applicable privacy and security obligations, including HIPAA requirements where applicable, 42 CFR Part 2 requirements where applicable, and relevant federal and state privacy requirements.

Audit Logging and Provenance

MedIQ shall maintain comprehensive records of system activity and data provenance.

Capabilities include:

  • Authentication logs
  • Authorization logs
  • Data access logs
  • Data modification logs
  • Eligibility execution logs
  • Rule execution logs
  • API activity logs
  • Administrative activity logs
  • Investigation activity logs
  • Model execution records
  • Configuration changes
  • Policy changes
  • Consent changes
  • Report generation records
  • Data lineage
  • Source identification
  • Timestamped events
  • Tamper-evident storage
  • Audit-log integrity verification
  • Historical reconstruction

Monitoring and Operations

MedIQ shall provide centralized operational monitoring for system reliability, integrations, security, data quality, and workflow performance.

Capabilities include:

  • Service health monitoring
  • API health monitoring
  • Workflow monitoring
  • Data pipeline monitoring
  • Integration monitoring
  • Security monitoring
  • Performance monitoring
  • Capacity monitoring
  • Error tracking
  • Alert management
  • Backup monitoring
  • Disaster recovery validation
  • Configuration auditing
  • Deployment version tracking
  • Rollback support
  • Maintenance workflows
  • Usage analytics

Accessibility and Civil Rights

MedIQ shall support accessible and equitable public services.

Capabilities include:

  • WCAG 2.1 accessibility support
  • Keyboard navigation
  • Screen-reader compatibility
  • Accessible forms
  • Accessible notifications
  • Multilingual interfaces
  • Language preference management
  • Accessibility testing
  • Bias monitoring
  • Disparate-impact analysis
  • Civil-rights safeguards
  • Human escalation
  • Accessible appeal processes

Governance and Compliance

MedIQ shall provide governance capabilities for maintaining legal, regulatory, policy, security, and operational accountability.

Capabilities include:

  • Federal regulatory guidance
  • State regulatory guidance
  • Policy versioning
  • Regulatory change tracking
  • Automated compliance checks
  • Legal audit support
  • Compliance evidence collection
  • Governance approvals
  • Model governance
  • Data governance
  • Access governance
  • Privacy governance
  • Security governance
  • Civil-rights monitoring
  • Audit readiness
  • Decision provenance

State-by-State Configuration

MedIQ shall support jurisdiction-specific configuration without requiring the core system to be rewritten for each state.

Capabilities include:

  • State eligibility rules
  • State Medicaid policies
  • State data sources
  • State workflow requirements
  • State reporting requirements
  • State privacy requirements
  • State-specific integrations
  • State-specific notification requirements
  • State-specific review processes
  • State-specific appeal requirements
  • Effective-date management
  • Jurisdiction-specific audit requirements

Optional Plugin Modules

Mobile Citizen Application Plugin

Provides mobile access to citizen services, notifications, status tracking, document submission, and secure communications.

Advanced Identity Plugin

Provides additional authorized identity verification providers, document analysis, liveness verification, and enhanced identity-risk analysis.

Fraud Intelligence Plugin

Provides advanced fraud pattern analysis, cross-program intelligence, predictive risk modeling, and expanded investigative analytics.

Federal Data Integration Plugin

Provides connectors for authorized federal data sources and federal program systems.

State Integration Plugin

Provides configurable adapters for individual state Medicaid systems and state-specific data sources.

Provider Intelligence Plugin

Analyzes provider relationships, utilization patterns, billing patterns, and other authorized provider data.

Advanced AI Plugin

Provides advanced machine learning, predictive modeling, federated learning, anomaly classification, and policy simulation capabilities.

Explainable AI Plugin

Provides detailed evidence-linked explanations for AI-generated risk indicators, recommendations, classifications, and analytical results.

Blockchain Audit Plugin

Provides an optional distributed audit mechanism for systems that require additional tamper-evidence or independently verifiable audit records.

Public Transparency Plugin

Provides configurable public reporting of aggregated program statistics, transition metrics, budget information, audit findings, and other information approved for public disclosure.

Multilingual Services Plugin

Provides expanded language support, translation workflows, localized communications, and multilingual citizen assistance.

AI Citizen Assistant Plugin

Provides conversational assistance for navigating MedIQ services, understanding requirements, locating information, and identifying next steps while clearly distinguishing guidance from official determinations.

Automated Compliance Plugin

Provides automated evaluation of configured workflows against applicable regulatory, policy, security, privacy, and governance requirements.

Predictive Policy Plugin

Provides scenario modeling for proposed policy changes and estimates potential effects on enrollment, costs, workload, coverage, and administrative operations.

Workforce Optimization Plugin

Provides staff workload analysis, review scheduling, resource allocation, queue optimization, and capacity forecasting.

Third-Party Benefits Plugin

Provides integration with additional authorized benefit programs and services to support coordinated eligibility and transition workflows.

Integration Marketplace Plugin

Provides a governed mechanism for installing, managing, validating, and monitoring third-party integration modules.


Specification Branding License (SBL)

Standard

Optional

  • Specification Branding License (SBL)

License & Notice Requirements

MedIQ is released under the GNU Affero General Public License v3.0 or later (AGPL-3.0+).

By contributing to this project, you agree that your contributions will also be released under this license.

Please note the following:

  • All contributions must comply with the AGPL-3.0+ terms.
  • Under Section 7 of the license, all redistributions, forks, and derivative works must preserve attribution to:
    Roxanne Ardary and roxanneardary.com.
  • MedIQ specifications are free to use with attribution. A Specification Branding License can be negotiated upon request.
  • The project’s notice.md file tracks attribution requirements and contributor acknowledgments. Any update that adds new contributors or modifies attribution should also update notice.md.
  • When submitting a pull request, ensure that any new files maintain the attribution headers where applicable.
  • Network-deployed versions of this software must also remain fully AGPL-3.0+ compliant, including exposure of source code modifications when applicable under the license.

For full legal details, please refer to the AGPL-3.0+ license and the project’s notice.md file.


Notice – MedIQ

Attribution Requirement: Under Section 7 of the AGPL 3.0+ license, all redistributions, forks, and derivative works, including network-deployed versions of this project, must provide attribution to Roxanne Ardary and roxanneardary.com.

Contributors

This file tracks contributors and their specific contributions to the project.

  • Roxanne Ardary, roxanneardary.com – March 30, 2026
    Created the MedIQ repository and defined the core system architecture for an AI-driven Medicaid to Medicare transition platform with integrated verification, fraud detection, and federated data design.
  • [Add other contributors here] – [Date]
    [Describe contribution in one sentence]

License – MedIQ

This repository is licensed under the GNU Affero General Public License v3.0 or later (AGPL-3.0+).

Key Points

  • You are free to use, modify, and distribute the code.
  • All redistributions, forks, and derivative works or network-deployed versions must also be licensed under AGPL-3.0+ and provide attribution to Roxanne Ardary and roxanneardary.com as required under Section 7 of the license.
  • The software is provided “as is,” without warranty of any kind.

For the full license text, see GNU AGPL-3.0 License.