What Is Delegated Risk in Healthcare? A Complete Guide for Health Plans, IPAs, and MSOs
Delegated risk transfers defined financial and operational responsibilities from health plans to IPAs, medical groups, and other organizations. Learn how capitation, DOFRs, claims, oversight, and reconciliation work together.
Delegated risk in healthcare is a contractual arrangement in which a health plan transfers financial responsibility for defined healthcare costs, responsibility for specified administrative functions, or both to another organization. The scope, payment method, performance requirements, and retained responsibilities depend on the governing agreement and applicable regulatory requirements.
Delegated risk is one of the most operationally significant forms of value-based care, particularly in markets where health plans contract with independent practice associations (IPAs), medical groups, and other risk-bearing organizations. It can give provider organizations greater responsibility for coordinating care and managing costs, but it also creates complex dependencies among contracts, capitation, claims systems, utilization management, financial reporting, and delegation oversight.
This guide explains how delegated risk works, who participates, how delegated organizations may be paid, how Divisions of Financial Responsibility (DOFRs) define service-level responsibility, and what leaders should evaluate before accepting or expanding risk.
1. What Is Delegated Risk in Healthcare?
Delegated risk is the transfer of defined financial or operational responsibilities from a health plan to another organization under a contract.
In a financial-risk arrangement, a health plan may pay a medical group, IPA, or other organization a prospective amount to accept responsibility for an agreed set of healthcare costs. Capitation, commonly expressed as a per-member-per-month (PMPM) payment, is one method used to fund that responsibility.
The word risk refers to uncertainty in the financial outcome. Actual costs may differ from the revenue or target established under the agreement. Depending on the contract, the delegated organization may retain some or all favorable performance and may bear some or all adverse performance, subject to provisions such as:
- Shared-risk percentages
- Withholds and incentive pools
- Risk corridors
- Stop-loss protection
- Reinsurance
- Quality requirements
- Reconciliation and settlement terms
- Limits on the categories or amounts of risk transferred
Administrative functions can also be delegated. Claims processing, utilization management, credentialing, quality reporting, and other functions may be performed by a delegate even when that entity does not bear the associated healthcare costs.
This distinction matters. Delegation describes who performs a function or accepts a responsibility. Capitation describes a method of payment. Financial risk describes exposure to variation in costs or performance. Those concepts frequently appear together, but they are not interchangeable.
2. How Does Delegated Risk Work?
A delegated arrangement begins with one or more governing agreements. The document names and structures vary. Depending on the parties and market, the relevant materials may include a master agreement, provider agreement, delegation agreement, risk agreement, participation agreement, DOFR schedule, amendments, benefit grids, exception tables, and operational policies.
Together, these materials establish several essential elements.
What is being transferred
The agreement should identify each delegated function and each category of healthcare costs included within the financial arrangement. A plan may delegate professional services while retaining institutional costs, or it may transfer a broader scope. Administrative delegation may be narrower or broader than the transferred financial risk.
Who is responsible
The contract identifies the entity accepting the delegated responsibility. That may be an IPA, medical group, another qualifying risk-bearing organization, or an administrative organization performing functions on behalf of the responsible entity.
How payment works
Payment may include capitation, fee-for-service reimbursement, shared savings, shared losses, incentive payments, risk-pool settlements, or a combination. The economic model should be evaluated together with the scope of responsibility.
How performance is measured
Agreements may establish requirements for claims accuracy and timeliness, utilization management, provider access, quality, reporting, data submission, member protections, audit cooperation, and financial solvency.
What the health plan retains
Delegation does not necessarily transfer every function or cost. The plan may retain specified services, approval rights, monitoring duties, member-facing responsibilities, and responsibility for complying with its own regulatory and contractual obligations.
After execution, contractual terms must become operational processes. Eligibility files determine which members are assigned. Capitation systems calculate payments. Claims and authorization platforms apply benefit, provider, and financial-responsibility rules. Finance teams monitor performance and reconcile differences. Oversight teams evaluate whether delegated functions meet contractual and regulatory standards.
The arrangement succeeds only when these layers remain aligned.
3. What Responsibilities Can a Health Plan Delegate?
The scope varies by agreement, product, line of business, and regulatory environment. Commonly delegated functions can include the following.
Financial responsibility for defined services
A plan may transfer responsibility for specified professional, institutional, ancillary, pharmacy, behavioral health, or other healthcare costs. The governing documents define which costs are included, retained, shared, or subject to exceptions.
Claims administration
A delegated entity or its administrator may receive, adjudicate, price, pay, deny, and report claims within the delegated scope. Responsibility rules may be implemented in platforms such as QNXT, HealthRules, Facets, EZ-CAP, Epic Tapestry, or internally developed systems.
Utilization management
The delegate may perform prior authorization, concurrent review, retrospective review, care coordination, or related activities for defined services. The delegation agreement should establish scope, decision standards, reporting, monitoring, and remedies.
Credentialing and provider-network functions
Plans may delegate defined credentialing or network-management activities, subject to applicable standards and the plan's oversight responsibilities.
Quality management and reporting
Delegates may collect and submit data, administer improvement activities, or support measurement and reporting obligations.
Member-facing and administrative functions
Depending on the arrangement, a delegate may perform specified customer-service, grievance, appeal, referral, or other administrative functions.
These functions do not have to move together. One organization might accept financial responsibility without processing claims. Another might process claims without bearing the costs being adjudicated. Leaders should identify separately who performs each function, who bears each cost, and who remains accountable for each requirement.
4. Who Participates in Delegated Risk?
Several organizational types may participate, but their roles should not be assumed from their names alone.
Health plans
Health plans contract with members, employers, government programs, and provider organizations. They may transfer defined responsibilities while retaining other functions and their applicable contractual and regulatory obligations.
Independent practice associations
An IPA is an organization through which independent physicians can contract collectively with health plans and coordinate administrative or clinical activities. Some IPAs accept capitation and financial risk. Others may participate under different payment and operational arrangements. An IPA should not be assumed to bear risk merely because it is an IPA.
Medical groups
Medical groups may employ or contract with physicians and may accept professional, institutional, or other financial responsibility. Structures vary substantially by organization and market.
Management services organizations
An MSO provides administrative, technical, financial, or operational services to medical groups, IPAs, health systems, or other organizations. Services may include claims administration, contracting support, analytics, network operations, compliance reporting, and financial management.
An MSO is not automatically a delegated entity or risk-bearing organization. Some MSOs operate only as service providers, while others may participate through contractual or affiliated structures that require separate analysis.
Risk-bearing organizations in California
California uses the term risk-bearing organization within a specific statutory and regulatory framework. The applicable definition concerns a lawfully organized group of physicians that delivers, furnishes, or otherwise arranges for healthcare services and accepts defined forms of financial risk from a health care service plan.
RBOs submit financial information that allows the California Department of Managed Health Care (DMHC) to monitor financial solvency. The DMHC publishes information about active capitated providers and RBO reporting requirements. DMHC: Risk-Bearing Organizations
An MSO supporting an RBO is not automatically an RBO itself. The relevant legal entity, contract, and allocation of financial risk must be identified.
Hospitals and health systems
Hospitals and health systems may participate directly in risk arrangements, support affiliated medical groups, enter shared-risk agreements, or provide services to members assigned to delegated organizations. Their financial exposure depends on the governing contracts and payment structure.
5. How Are Delegated Organizations Paid?
Capitation is a common payment method in delegated-risk arrangements, but it is not the only one.
Professional capitation
An organization may receive prospective payment for a defined range of professional services while the health plan or another party retains institutional and other costs.
Broader or global capitation
Some arrangements transfer responsibility for a broader combination of professional, institutional, ancillary, pharmacy, behavioral health, or other services. Even arrangements described as global may contain exclusions, stop-loss provisions, carve-outs, or shared-risk components.
Shared-risk arrangements
The parties may compare actual performance with a target and divide favorable or unfavorable results according to contractual terms. Payment can depend on quality, utilization, cost, and other performance measures.
Subcapitation
A delegated organization may make prospective payments to a downstream provider or specialty organization for defined services. That downstream arrangement does not necessarily eliminate the first organization's obligations to the health plan.
Mixed payment models
One agreement can combine capitation, fee-for-service claims, incentives, withholds, risk pools, and retrospective settlements. For example, professional services may be capitated while certain high-cost services remain subject to separate reimbursement or risk sharing.
For this reason, a PMPM rate cannot be evaluated in isolation. Leaders must understand what the payment covers, which services are excluded, how membership is determined, what adjustments apply, and how final settlements are calculated.
6. What Is Capitation?
Capitation is a prospective payment method under which an organization receives a fixed amount for each enrolled or assigned member over a defined period to provide, arrange, or accept financial responsibility for specified services.
The payment is commonly expressed on a PMPM basis. It may vary by product, age, geography, risk adjustment, benefit design, eligibility category, or other factors established under the contract.
Capitation changes the relationship between service volume and revenue. Fee-for-service generally rewards additional billable services. Capitation creates a fixed budget for an agreed scope, which can support investments in prevention, care management, chronic-disease management, and coordination.
It also creates risks. A rate may be inadequate. Membership data may be wrong. A high-cost event may exceed expectations. The organization may lack timely utilization information. Poorly designed incentives can also encourage inappropriate reductions in necessary care. Quality measurement, member protections, utilization controls, stop-loss arrangements, and oversight therefore remain important.
The Centers for Medicare & Medicaid Services describes capitation and prepayment as payment approaches used in multiple programs, but the exact economic and operational terms depend on the applicable model and agreement. CMS: Capitation and Pre-payment
7. What Is a DOFR?
A Division of Financial Responsibility, commonly called a DOFR, is a contractual matrix, schedule, exhibit, or related set of materials that allocates financial responsibility for defined healthcare services among parties to a delegated arrangement.
A DOFR may assign responsibility to:
- A medical group, IPA, or other delegated entity
- The health plan
- A facility or institutional risk pool
- A specialty organization
- More than one party through shared, split, threshold-based, or exception-based provisions
The form varies. Some contracts contain one matrix. Others rely on a DOFR together with amendments, benefit grids, drug tables, code crosswalks, exception schedules, and product-specific rules.
The DOFR provides the contractual foundation for financial-responsibility decisions. Claims systems operationalize those terms through configuration that may evaluate member product, date of service, procedure and revenue codes, place of service, provider characteristics, network status, drug identifiers, and contract-specific exceptions.
A public Alameda County Health example illustrates how responsibility can vary across service categories and lines of business. It should be treated as an example rather than a universal industry template. Alameda County Health DOFR example
For a deeper operational explanation, read What Is a DOFR? The Complete Guide to Division of Financial Responsibility.
8. How Do DOFRs Define Financial Responsibility?
Many delegated arrangements can be understood through three common responsibility categories, although the contract may use different terminology or additional structures.
Delegated or capitated responsibility
The delegated organization bears responsibility for services included within the agreed scope. The economic treatment may involve capitation, a risk pool, shared risk, or another payment arrangement.
Health-plan responsibility
The health plan retains responsibility for services that were not transferred, were expressly retained, or fall within a contractual exception.
Separately administered or carved-out responsibility
A specialty organization or another defined party may administer or bear responsibility for particular services. The health plan may also retain a service described operationally as carved out. Terminology varies, so the contract must control the classification.
Responsibility can also be divided by professional and facility components, place of service, network status, geography, dollar threshold, provider type, product, diagnosis, or another negotiated condition.
This is why a service name alone is rarely enough. “Injectable medication,” “chemotherapy,” “diagnostic testing,” or “outpatient facility” may require additional claim and contract context before responsibility can be assigned accurately.
9. What Does the Health Plan Retain?
The retained scope depends on the agreement and regulatory context. It commonly includes some combination of the following.
Retained healthcare costs and functions
The plan may retain financial responsibility for specified services and continue performing claims, authorization, credentialing, network, quality, or member functions that were not delegated.
Oversight and monitoring
The plan may be required to monitor delegated performance, receive reports, audit activities, require corrective action, or revoke delegation when performance is unsatisfactory.
Medicare Advantage responsibility
Under 42 CFR § 422.504(i), a Medicare Advantage organization maintains ultimate responsibility for adhering to the terms and conditions of its contract with CMS, notwithstanding its relationships with first-tier, downstream, and related entities. Delegated contracts must identify activities and reporting responsibilities, provide remedies, and require ongoing monitoring. 42 CFR § 422.504
Medicaid managed-care responsibility
Under 42 CFR § 438.230, covered Medicaid managed-care entities maintain ultimate responsibility for complying with their contracts with the state notwithstanding their subcontractor relationships. Written arrangements must define delegated obligations and remedies and preserve audit rights. 42 CFR § 438.230
These requirements should not be generalized beyond their applicable programs. Commercial arrangements, state requirements, and individual contracts require separate analysis.
10. How Do Carve-Ins and Carve-Outs Work?
A carve-out generally removes a defined service or responsibility from the scope assigned to one party. The health plan may retain it or assign it separately to another organization. A carve-in generally adds a service or responsibility to the delegated scope.
Commonly discussed areas include behavioral health, pharmacy, vision, dental, transportation, transplant services, dialysis, specialty drugs, and other services requiring specialized networks or administration. Actual treatment varies by agreement.
A carve-in or carve-out may affect capitation, risk targets, withholds, or other economic terms, but no universal adjustment should be assumed. The contract should specify the financial effect.
Operationally, a change may require updates to:
- Contract and DOFR documents
- Effective-date records
- Benefit and exception tables
- Claims configuration
- Authorization rules
- Provider instructions
- Vendor routing
- Reporting and reconciliation logic
If the governing documents and operational systems are updated at different times, claims can continue processing under obsolete responsibility rules without creating a denial or visible system failure.
11. IPA vs. MSO vs. Risk-Bearing Organization
These terms describe different dimensions of an arrangement.
IPA
An IPA enables independent physicians or practices to participate collectively in health-plan contracting and coordinated administrative or clinical activities. An IPA may accept capitation and financial risk, but its actual responsibilities depend on its contracts.
MSO
An MSO supplies administrative or operational capabilities. It may support claims, analytics, contracting, provider data, reporting, technology, or finance. It does not automatically bear risk merely because it supports a risk-bearing client.
RBO
In California, RBO is a regulatory classification tied to the acceptance of defined financial risk by a qualifying organization. RBOs have financial-reporting and solvency-monitoring obligations administered by the DMHC.
The roles can be layered. A health plan may transfer risk to an IPA or medical group that qualifies as an RBO. That organization may contract with an MSO for administrative support. The governing agreements should identify which legal entity bears risk, which performs each function, and which holds each obligation.
12. How Does Delegated Risk Support Value-Based Care?
Delegated risk can support value-based care by giving provider organizations financial responsibility for the cost and coordination of care across a population.
When designed appropriately, this can create incentives to:
- Prevent avoidable complications
- Coordinate care across settings
- Manage chronic conditions proactively
- Reduce duplicative or low-value services
- Invest in population-health infrastructure
- Use data to identify rising-risk members
- Improve access to timely outpatient care
Delegation is not synonymous with value-based care. Value-based arrangements also include quality incentives, bundled payments, shared savings, shared losses, accountable-care models, and other approaches that may not involve a health plan delegating responsibility to an IPA or medical group.
Accountable Care Organizations illustrate the distinction. Medicare ACO programs create financial accountability against benchmarks, but participation in the Medicare Shared Savings Program does not by itself establish a health plan-to-provider delegation arrangement, capitation, or DOFR use. The models share an emphasis on population-level performance but operate under different contractual structures.
Financial incentives alone do not guarantee better care. Rate adequacy, clinical capability, quality safeguards, patient protections, data access, and governance determine whether a delegated model supports both financial sustainability and appropriate care.
13. How Does Delegated Risk Affect Claims?
Delegated risk can change who receives, adjudicates, pays, reports, and reconciles claims. The workflow depends on which claims functions and healthcare costs were transferred.
When claims administration is delegated, the responsible organization or its administrator may apply rules involving:
- Member eligibility and product
- Date of service
- Financial-responsibility category
- Procedure, revenue, diagnosis, and drug codes
- Place of service and bill type
- Provider type, specialty, and network status
- Benefits, exclusions, and authorizations
- Contract amendments and exceptions
The system can process a claim successfully while assigning its cost to the wrong party. If the configured rule is technically valid but contractually incorrect, the claim may not deny or suspend. The discrepancy may surface through claim testing, financial-pattern monitoring, a provider inquiry, a contract-to-configuration audit, or reconciliation.
Authorization and financial responsibility are related but distinct. An authorization decision does not automatically establish which party ultimately owes the claim. Both processes must use current, compatible contract and benefit rules.
When organizations provide conflicting routing or payment instructions, providers can experience delays, rework, disputes, and additional administrative burden. Accurate responsibility rules therefore affect not only the plan and delegate but also downstream providers and members.
14. What Are the Principal Operational Risks?
Contract-to-configuration mismatch
The production rules may omit an amendment, apply the wrong effective date, misinterpret an exception, or rely on an outdated table.
Incomplete source documents
Teams may configure from a DOFR while missing another exhibit, amendment, benefit grid, or crosswalk that changes the result.
Configuration drift
Contracts, code sets, drugs, benefits, products, vendors, and networks change over time. A configuration that was correct at implementation can become obsolete.
Institutional-knowledge dependence
Interpretive decisions may live in email, spreadsheets, or individual experience rather than a governed source of truth.
Data and effective-date errors
Incorrect eligibility, product mapping, provider data, or contract versioning can produce the wrong result even when the responsibility logic itself is sound.
Rate and actuarial risk
Capitation may not reflect actual utilization, acuity, benefits, geographic costs, or the precise scope transferred.
Coordination risk
Plans, delegates, MSOs, providers, and specialty organizations may maintain different versions of responsibility rules or implement changes on different timelines.
Oversight gaps
An oversight program may measure timeliness and reporting without testing whether production responsibility rules match the governing agreement.
15. What Is Delegation Oversight?
Delegation oversight is the process through which a health plan evaluates whether delegated functions are being performed according to the governing agreement and applicable requirements.
A mature program may include:
- Pre-delegation capability assessment
- Written identification of delegated activities and reporting duties
- Performance standards and data submissions
- Ongoing monitoring
- Periodic audits or validation
- Corrective-action procedures
- Remedies or revocation provisions
- Records and audit access
- Reassumption and continuity planning
The applicable requirements vary. Medicare Advantage and Medicaid managed care have specific federal provisions governing delegation and subcontractor relationships. State law, accreditation standards, and the contract can add further obligations.
DOFR configuration deserves an explicit place in oversight when financial responsibility or claims administration is delegated. Reviewing claim timeliness does not establish that the correct party was charged. Configuration verification asks a different question: do the rules used in production reflect the current governing documents?
16. How Are Delegated Arrangements Reconciled?
“Reconciliation” can refer to several distinct controls. They should not be treated as one universal annual process.
Membership and eligibility reconciliation
The parties compare assigned membership, effective dates, retroactive changes, and product information.
Capitation-payment reconciliation
Expected PMPM payments are compared with actual payments, adjustments, deductions, and retroactivity.
Claims financial-responsibility reconciliation
Claims are evaluated to determine whether the party that paid or absorbed the cost matched the governing agreement.
Risk-pool and shared-risk settlement
The parties calculate performance against contractual targets and apply exclusions, corridors, withholds, quality terms, stop-loss recoveries, and sharing percentages.
Vendor or carve-out reconciliation
Claims and payments are reviewed across the health plan, delegated organization, and separately responsible organizations.
The timing can be monthly, quarterly, annually, event-driven, or otherwise specified. Reconciliation can identify and quantify discrepancies, but it should not be the only control. Continuous monitoring, representative claim testing, change validation, and contract-to-configuration comparison can find problems earlier.
17. What Should Leaders Evaluate Before Accepting Risk?
Contract clarity
Can the organization identify exactly which services, members, products, functions, and effective periods are included? Are exceptions and dispute procedures clear?
Rate adequacy
Does the organization have credible utilization, claims, benefit, and membership information? Has it modeled adverse scenarios and contract-specific exclusions?
Capital and protection
Are reserves, working capital, stop-loss coverage, and risk corridors sufficient for the exposure?
Clinical capability
Can the organization manage utilization, coordinate care, support high-risk members, and maintain appropriate access and quality?
Claims and administrative infrastructure
Can it implement contract-specific rules, process claims accurately, preserve audit trails, and report required information?
DOFR governance
Can the organization trace production rules to governing language, manage versions and effective dates, test edge cases, and validate changes?
Data access
Will it receive timely, complete membership, claims, encounter, authorization, provider, and financial data?
Oversight and compliance
Can it meet reporting, audit, member-protection, solvency, and other applicable requirements?
Organizational commitment
Delegated risk requires sustained leadership, staffing, technology, clinical operations, and financial discipline. It should not be accepted as a contract term without a corresponding operating model.
18. Frequently Asked Questions
Is delegated risk the same as capitation?
No. Delegated risk describes the transfer of defined financial responsibility. Capitation is a payment method commonly used to fund that responsibility. Administrative functions can also be delegated without transferring healthcare-cost risk.
Does every delegated arrangement use a DOFR?
Not necessarily under that name or format. Financial responsibility may appear in a DOFR, risk matrix, responsibility schedule, contract exhibit, benefit grid, or several related documents.
Can an MSO accept delegated risk?
An MSO is not automatically risk bearing. Whether a particular MSO accepts risk depends on its legal structure, contracts, regulatory status, and actual allocation of financial responsibility.
Is delegated risk the same as an ACO arrangement?
No. Some ACO models involve upside and downside financial risk, but they do not automatically involve health-plan delegation, capitation, or DOFRs. The governing program and contracts determine the structure.
How often should delegated arrangements be reviewed?
Review should occur when relevant contracts, amendments, benefits, products, codes, vendors, systems, or regulatory requirements change. Periodic verification should supplement event-based review. No universal annual or quarterly schedule fits every arrangement.
19. Sources and Methodology
This guide combines primary regulatory sources, public program materials, public DOFR examples, and practitioner-reviewed operational knowledge. It describes common structures rather than prescribing one universal model.
Primary sources
- 42 CFR § 422.504, Medicare Advantage contract provisions
- 42 CFR § 438.230, Medicaid managed-care subcontractual relationships and delegation
- California DMHC, Risk-Bearing Organizations
- CMS, Capitation and Pre-payment
- Alameda County Health, public Division of Financial Responsibility example
Written by: Michael Riley, Co-Founder and Chief Product Officer of Gabeo.ai
Reviewed for operational accuracy by: Octavio Campos, Director of Operations at Guidant Health, with more than 20 years of DOFR experience
Last substantively reviewed: August 27, 2026
This material is educational. Financial responsibility, delegation, payment, coverage, and oversight depend on applicable requirements, member benefits, governing agreements, amendments, and current operational configuration.
20. Continue Learning
- What Is a DOFR? The Complete Guide to Division of Financial Responsibility
- Why DOFR Errors Don't Generate Denials
- The Three-Way Model of Financial Responsibility
- Why Static DOFR Configuration Eventually Fails
- The Delegation Oversight Blind Spot
- Gabeo DOFR Resource Center
21. How ARIA Supports DOFR Accuracy
Delegated-risk operations depend on alignment among contracts, DOFRs, system rules, and claim outcomes.
ARIA helps health plans, IPAs, MSOs, and other delegated-risk organizations codify financial-responsibility terms and evaluate claims for potential responsibility mismatches. It is designed to support contract-to-claim analysis across complex service categories, amendments, and payer arrangements while preserving the evidence needed for operational review.
ARIA complements existing claims platforms and human decision-making. Confirmed findings, remediation, recovery, and prospective configuration changes remain subject to the governing contract and the organization's validation and dispute processes.
To learn more, explore ARIA for delegated risk.