CAHP 2026 Catch us at the CAHP Annual Conference, Oct 19–21 in Palm Desert. Gabeo is a proud Gold sponsor. See the conference
Delegated RiskEducationValue-Based CareHealth Plan OperationsFinancial Responsibility

What Is Delegated Risk in Healthcare? A Complete Guide for Health Plans, IPAs, and MSOs

Delegated risk transfers defined financial and operational responsibilities from health plans to IPAs, medical groups, and other organizations. Learn how capitation, DOFRs, claims, oversight, and reconciliation work together.

What Is Delegated Risk in Healthcare? A Complete Guide for Health Plans, IPAs, and MSOs

Delegated risk in healthcare is a contractual arrangement in which a health plan transfers financial responsibility for defined healthcare costs, responsibility for specified administrative functions, or both to another organization. The scope, payment method, performance requirements, and retained responsibilities depend on the governing agreement and applicable regulatory requirements.

Delegated risk is one of the most operationally significant forms of value-based care, particularly in markets where health plans contract with independent practice associations (IPAs), medical groups, and other risk-bearing organizations. It can give provider organizations greater responsibility for coordinating care and managing costs, but it also creates complex dependencies among contracts, capitation, claims systems, utilization management, financial reporting, and delegation oversight.

This guide explains how delegated risk works, who participates, how delegated organizations may be paid, how Divisions of Financial Responsibility (DOFRs) define service-level responsibility, and what leaders should evaluate before accepting or expanding risk.

1. What Is Delegated Risk in Healthcare?

Delegated risk is the transfer of defined financial or operational responsibilities from a health plan to another organization under a contract.

In a financial-risk arrangement, a health plan may pay a medical group, IPA, or other organization a prospective amount to accept responsibility for an agreed set of healthcare costs. Capitation, commonly expressed as a per-member-per-month (PMPM) payment, is one method used to fund that responsibility.

The word risk refers to uncertainty in the financial outcome. Actual costs may differ from the revenue or target established under the agreement. Depending on the contract, the delegated organization may retain some or all favorable performance and may bear some or all adverse performance, subject to provisions such as:

Administrative functions can also be delegated. Claims processing, utilization management, credentialing, quality reporting, and other functions may be performed by a delegate even when that entity does not bear the associated healthcare costs.

This distinction matters. Delegation describes who performs a function or accepts a responsibility. Capitation describes a method of payment. Financial risk describes exposure to variation in costs or performance. Those concepts frequently appear together, but they are not interchangeable.

2. How Does Delegated Risk Work?

A delegated arrangement begins with one or more governing agreements. The document names and structures vary. Depending on the parties and market, the relevant materials may include a master agreement, provider agreement, delegation agreement, risk agreement, participation agreement, DOFR schedule, amendments, benefit grids, exception tables, and operational policies.

Together, these materials establish several essential elements.

What is being transferred

The agreement should identify each delegated function and each category of healthcare costs included within the financial arrangement. A plan may delegate professional services while retaining institutional costs, or it may transfer a broader scope. Administrative delegation may be narrower or broader than the transferred financial risk.

Who is responsible

The contract identifies the entity accepting the delegated responsibility. That may be an IPA, medical group, another qualifying risk-bearing organization, or an administrative organization performing functions on behalf of the responsible entity.

How payment works

Payment may include capitation, fee-for-service reimbursement, shared savings, shared losses, incentive payments, risk-pool settlements, or a combination. The economic model should be evaluated together with the scope of responsibility.

How performance is measured

Agreements may establish requirements for claims accuracy and timeliness, utilization management, provider access, quality, reporting, data submission, member protections, audit cooperation, and financial solvency.

What the health plan retains

Delegation does not necessarily transfer every function or cost. The plan may retain specified services, approval rights, monitoring duties, member-facing responsibilities, and responsibility for complying with its own regulatory and contractual obligations.

After execution, contractual terms must become operational processes. Eligibility files determine which members are assigned. Capitation systems calculate payments. Claims and authorization platforms apply benefit, provider, and financial-responsibility rules. Finance teams monitor performance and reconcile differences. Oversight teams evaluate whether delegated functions meet contractual and regulatory standards.

The arrangement succeeds only when these layers remain aligned.

3. What Responsibilities Can a Health Plan Delegate?

The scope varies by agreement, product, line of business, and regulatory environment. Commonly delegated functions can include the following.

Financial responsibility for defined services

A plan may transfer responsibility for specified professional, institutional, ancillary, pharmacy, behavioral health, or other healthcare costs. The governing documents define which costs are included, retained, shared, or subject to exceptions.

Claims administration

A delegated entity or its administrator may receive, adjudicate, price, pay, deny, and report claims within the delegated scope. Responsibility rules may be implemented in platforms such as QNXT, HealthRules, Facets, EZ-CAP, Epic Tapestry, or internally developed systems.

Utilization management

The delegate may perform prior authorization, concurrent review, retrospective review, care coordination, or related activities for defined services. The delegation agreement should establish scope, decision standards, reporting, monitoring, and remedies.

Credentialing and provider-network functions

Plans may delegate defined credentialing or network-management activities, subject to applicable standards and the plan's oversight responsibilities.

Quality management and reporting

Delegates may collect and submit data, administer improvement activities, or support measurement and reporting obligations.

Member-facing and administrative functions

Depending on the arrangement, a delegate may perform specified customer-service, grievance, appeal, referral, or other administrative functions.

These functions do not have to move together. One organization might accept financial responsibility without processing claims. Another might process claims without bearing the costs being adjudicated. Leaders should identify separately who performs each function, who bears each cost, and who remains accountable for each requirement.

4. Who Participates in Delegated Risk?

Several organizational types may participate, but their roles should not be assumed from their names alone.

Health plans

Health plans contract with members, employers, government programs, and provider organizations. They may transfer defined responsibilities while retaining other functions and their applicable contractual and regulatory obligations.

Independent practice associations

An IPA is an organization through which independent physicians can contract collectively with health plans and coordinate administrative or clinical activities. Some IPAs accept capitation and financial risk. Others may participate under different payment and operational arrangements. An IPA should not be assumed to bear risk merely because it is an IPA.

Medical groups

Medical groups may employ or contract with physicians and may accept professional, institutional, or other financial responsibility. Structures vary substantially by organization and market.

Management services organizations

An MSO provides administrative, technical, financial, or operational services to medical groups, IPAs, health systems, or other organizations. Services may include claims administration, contracting support, analytics, network operations, compliance reporting, and financial management.

An MSO is not automatically a delegated entity or risk-bearing organization. Some MSOs operate only as service providers, while others may participate through contractual or affiliated structures that require separate analysis.

Risk-bearing organizations in California

California uses the term risk-bearing organization within a specific statutory and regulatory framework. The applicable definition concerns a lawfully organized group of physicians that delivers, furnishes, or otherwise arranges for healthcare services and accepts defined forms of financial risk from a health care service plan.

RBOs submit financial information that allows the California Department of Managed Health Care (DMHC) to monitor financial solvency. The DMHC publishes information about active capitated providers and RBO reporting requirements. DMHC: Risk-Bearing Organizations

An MSO supporting an RBO is not automatically an RBO itself. The relevant legal entity, contract, and allocation of financial risk must be identified.

Hospitals and health systems

Hospitals and health systems may participate directly in risk arrangements, support affiliated medical groups, enter shared-risk agreements, or provide services to members assigned to delegated organizations. Their financial exposure depends on the governing contracts and payment structure.

5. How Are Delegated Organizations Paid?

Capitation is a common payment method in delegated-risk arrangements, but it is not the only one.

Professional capitation

An organization may receive prospective payment for a defined range of professional services while the health plan or another party retains institutional and other costs.

Broader or global capitation

Some arrangements transfer responsibility for a broader combination of professional, institutional, ancillary, pharmacy, behavioral health, or other services. Even arrangements described as global may contain exclusions, stop-loss provisions, carve-outs, or shared-risk components.

Shared-risk arrangements

The parties may compare actual performance with a target and divide favorable or unfavorable results according to contractual terms. Payment can depend on quality, utilization, cost, and other performance measures.

Subcapitation

A delegated organization may make prospective payments to a downstream provider or specialty organization for defined services. That downstream arrangement does not necessarily eliminate the first organization's obligations to the health plan.

Mixed payment models

One agreement can combine capitation, fee-for-service claims, incentives, withholds, risk pools, and retrospective settlements. For example, professional services may be capitated while certain high-cost services remain subject to separate reimbursement or risk sharing.

For this reason, a PMPM rate cannot be evaluated in isolation. Leaders must understand what the payment covers, which services are excluded, how membership is determined, what adjustments apply, and how final settlements are calculated.

6. What Is Capitation?

Capitation is a prospective payment method under which an organization receives a fixed amount for each enrolled or assigned member over a defined period to provide, arrange, or accept financial responsibility for specified services.

The payment is commonly expressed on a PMPM basis. It may vary by product, age, geography, risk adjustment, benefit design, eligibility category, or other factors established under the contract.

Capitation changes the relationship between service volume and revenue. Fee-for-service generally rewards additional billable services. Capitation creates a fixed budget for an agreed scope, which can support investments in prevention, care management, chronic-disease management, and coordination.

It also creates risks. A rate may be inadequate. Membership data may be wrong. A high-cost event may exceed expectations. The organization may lack timely utilization information. Poorly designed incentives can also encourage inappropriate reductions in necessary care. Quality measurement, member protections, utilization controls, stop-loss arrangements, and oversight therefore remain important.

The Centers for Medicare & Medicaid Services describes capitation and prepayment as payment approaches used in multiple programs, but the exact economic and operational terms depend on the applicable model and agreement. CMS: Capitation and Pre-payment

7. What Is a DOFR?

A Division of Financial Responsibility, commonly called a DOFR, is a contractual matrix, schedule, exhibit, or related set of materials that allocates financial responsibility for defined healthcare services among parties to a delegated arrangement.

A DOFR may assign responsibility to:

The form varies. Some contracts contain one matrix. Others rely on a DOFR together with amendments, benefit grids, drug tables, code crosswalks, exception schedules, and product-specific rules.

The DOFR provides the contractual foundation for financial-responsibility decisions. Claims systems operationalize those terms through configuration that may evaluate member product, date of service, procedure and revenue codes, place of service, provider characteristics, network status, drug identifiers, and contract-specific exceptions.

A public Alameda County Health example illustrates how responsibility can vary across service categories and lines of business. It should be treated as an example rather than a universal industry template. Alameda County Health DOFR example

For a deeper operational explanation, read What Is a DOFR? The Complete Guide to Division of Financial Responsibility.

8. How Do DOFRs Define Financial Responsibility?

Many delegated arrangements can be understood through three common responsibility categories, although the contract may use different terminology or additional structures.

Delegated or capitated responsibility

The delegated organization bears responsibility for services included within the agreed scope. The economic treatment may involve capitation, a risk pool, shared risk, or another payment arrangement.

Health-plan responsibility

The health plan retains responsibility for services that were not transferred, were expressly retained, or fall within a contractual exception.

Separately administered or carved-out responsibility

A specialty organization or another defined party may administer or bear responsibility for particular services. The health plan may also retain a service described operationally as carved out. Terminology varies, so the contract must control the classification.

Responsibility can also be divided by professional and facility components, place of service, network status, geography, dollar threshold, provider type, product, diagnosis, or another negotiated condition.

This is why a service name alone is rarely enough. “Injectable medication,” “chemotherapy,” “diagnostic testing,” or “outpatient facility” may require additional claim and contract context before responsibility can be assigned accurately.

9. What Does the Health Plan Retain?

The retained scope depends on the agreement and regulatory context. It commonly includes some combination of the following.

Retained healthcare costs and functions

The plan may retain financial responsibility for specified services and continue performing claims, authorization, credentialing, network, quality, or member functions that were not delegated.

Oversight and monitoring

The plan may be required to monitor delegated performance, receive reports, audit activities, require corrective action, or revoke delegation when performance is unsatisfactory.

Medicare Advantage responsibility

Under 42 CFR § 422.504(i), a Medicare Advantage organization maintains ultimate responsibility for adhering to the terms and conditions of its contract with CMS, notwithstanding its relationships with first-tier, downstream, and related entities. Delegated contracts must identify activities and reporting responsibilities, provide remedies, and require ongoing monitoring. 42 CFR § 422.504

Medicaid managed-care responsibility

Under 42 CFR § 438.230, covered Medicaid managed-care entities maintain ultimate responsibility for complying with their contracts with the state notwithstanding their subcontractor relationships. Written arrangements must define delegated obligations and remedies and preserve audit rights. 42 CFR § 438.230

These requirements should not be generalized beyond their applicable programs. Commercial arrangements, state requirements, and individual contracts require separate analysis.

10. How Do Carve-Ins and Carve-Outs Work?

A carve-out generally removes a defined service or responsibility from the scope assigned to one party. The health plan may retain it or assign it separately to another organization. A carve-in generally adds a service or responsibility to the delegated scope.

Commonly discussed areas include behavioral health, pharmacy, vision, dental, transportation, transplant services, dialysis, specialty drugs, and other services requiring specialized networks or administration. Actual treatment varies by agreement.

A carve-in or carve-out may affect capitation, risk targets, withholds, or other economic terms, but no universal adjustment should be assumed. The contract should specify the financial effect.

Operationally, a change may require updates to:

If the governing documents and operational systems are updated at different times, claims can continue processing under obsolete responsibility rules without creating a denial or visible system failure.

11. IPA vs. MSO vs. Risk-Bearing Organization

These terms describe different dimensions of an arrangement.

IPA

An IPA enables independent physicians or practices to participate collectively in health-plan contracting and coordinated administrative or clinical activities. An IPA may accept capitation and financial risk, but its actual responsibilities depend on its contracts.

MSO

An MSO supplies administrative or operational capabilities. It may support claims, analytics, contracting, provider data, reporting, technology, or finance. It does not automatically bear risk merely because it supports a risk-bearing client.

RBO

In California, RBO is a regulatory classification tied to the acceptance of defined financial risk by a qualifying organization. RBOs have financial-reporting and solvency-monitoring obligations administered by the DMHC.

The roles can be layered. A health plan may transfer risk to an IPA or medical group that qualifies as an RBO. That organization may contract with an MSO for administrative support. The governing agreements should identify which legal entity bears risk, which performs each function, and which holds each obligation.

12. How Does Delegated Risk Support Value-Based Care?

Delegated risk can support value-based care by giving provider organizations financial responsibility for the cost and coordination of care across a population.

When designed appropriately, this can create incentives to:

Delegation is not synonymous with value-based care. Value-based arrangements also include quality incentives, bundled payments, shared savings, shared losses, accountable-care models, and other approaches that may not involve a health plan delegating responsibility to an IPA or medical group.

Accountable Care Organizations illustrate the distinction. Medicare ACO programs create financial accountability against benchmarks, but participation in the Medicare Shared Savings Program does not by itself establish a health plan-to-provider delegation arrangement, capitation, or DOFR use. The models share an emphasis on population-level performance but operate under different contractual structures.

Financial incentives alone do not guarantee better care. Rate adequacy, clinical capability, quality safeguards, patient protections, data access, and governance determine whether a delegated model supports both financial sustainability and appropriate care.

13. How Does Delegated Risk Affect Claims?

Delegated risk can change who receives, adjudicates, pays, reports, and reconciles claims. The workflow depends on which claims functions and healthcare costs were transferred.

When claims administration is delegated, the responsible organization or its administrator may apply rules involving:

The system can process a claim successfully while assigning its cost to the wrong party. If the configured rule is technically valid but contractually incorrect, the claim may not deny or suspend. The discrepancy may surface through claim testing, financial-pattern monitoring, a provider inquiry, a contract-to-configuration audit, or reconciliation.

Authorization and financial responsibility are related but distinct. An authorization decision does not automatically establish which party ultimately owes the claim. Both processes must use current, compatible contract and benefit rules.

When organizations provide conflicting routing or payment instructions, providers can experience delays, rework, disputes, and additional administrative burden. Accurate responsibility rules therefore affect not only the plan and delegate but also downstream providers and members.

14. What Are the Principal Operational Risks?

Contract-to-configuration mismatch

The production rules may omit an amendment, apply the wrong effective date, misinterpret an exception, or rely on an outdated table.

Incomplete source documents

Teams may configure from a DOFR while missing another exhibit, amendment, benefit grid, or crosswalk that changes the result.

Configuration drift

Contracts, code sets, drugs, benefits, products, vendors, and networks change over time. A configuration that was correct at implementation can become obsolete.

Institutional-knowledge dependence

Interpretive decisions may live in email, spreadsheets, or individual experience rather than a governed source of truth.

Data and effective-date errors

Incorrect eligibility, product mapping, provider data, or contract versioning can produce the wrong result even when the responsibility logic itself is sound.

Rate and actuarial risk

Capitation may not reflect actual utilization, acuity, benefits, geographic costs, or the precise scope transferred.

Coordination risk

Plans, delegates, MSOs, providers, and specialty organizations may maintain different versions of responsibility rules or implement changes on different timelines.

Oversight gaps

An oversight program may measure timeliness and reporting without testing whether production responsibility rules match the governing agreement.

15. What Is Delegation Oversight?

Delegation oversight is the process through which a health plan evaluates whether delegated functions are being performed according to the governing agreement and applicable requirements.

A mature program may include:

The applicable requirements vary. Medicare Advantage and Medicaid managed care have specific federal provisions governing delegation and subcontractor relationships. State law, accreditation standards, and the contract can add further obligations.

DOFR configuration deserves an explicit place in oversight when financial responsibility or claims administration is delegated. Reviewing claim timeliness does not establish that the correct party was charged. Configuration verification asks a different question: do the rules used in production reflect the current governing documents?

16. How Are Delegated Arrangements Reconciled?

“Reconciliation” can refer to several distinct controls. They should not be treated as one universal annual process.

Membership and eligibility reconciliation

The parties compare assigned membership, effective dates, retroactive changes, and product information.

Capitation-payment reconciliation

Expected PMPM payments are compared with actual payments, adjustments, deductions, and retroactivity.

Claims financial-responsibility reconciliation

Claims are evaluated to determine whether the party that paid or absorbed the cost matched the governing agreement.

Risk-pool and shared-risk settlement

The parties calculate performance against contractual targets and apply exclusions, corridors, withholds, quality terms, stop-loss recoveries, and sharing percentages.

Vendor or carve-out reconciliation

Claims and payments are reviewed across the health plan, delegated organization, and separately responsible organizations.

The timing can be monthly, quarterly, annually, event-driven, or otherwise specified. Reconciliation can identify and quantify discrepancies, but it should not be the only control. Continuous monitoring, representative claim testing, change validation, and contract-to-configuration comparison can find problems earlier.

17. What Should Leaders Evaluate Before Accepting Risk?

Contract clarity

Can the organization identify exactly which services, members, products, functions, and effective periods are included? Are exceptions and dispute procedures clear?

Rate adequacy

Does the organization have credible utilization, claims, benefit, and membership information? Has it modeled adverse scenarios and contract-specific exclusions?

Capital and protection

Are reserves, working capital, stop-loss coverage, and risk corridors sufficient for the exposure?

Clinical capability

Can the organization manage utilization, coordinate care, support high-risk members, and maintain appropriate access and quality?

Claims and administrative infrastructure

Can it implement contract-specific rules, process claims accurately, preserve audit trails, and report required information?

DOFR governance

Can the organization trace production rules to governing language, manage versions and effective dates, test edge cases, and validate changes?

Data access

Will it receive timely, complete membership, claims, encounter, authorization, provider, and financial data?

Oversight and compliance

Can it meet reporting, audit, member-protection, solvency, and other applicable requirements?

Organizational commitment

Delegated risk requires sustained leadership, staffing, technology, clinical operations, and financial discipline. It should not be accepted as a contract term without a corresponding operating model.

18. Frequently Asked Questions

Is delegated risk the same as capitation?

No. Delegated risk describes the transfer of defined financial responsibility. Capitation is a payment method commonly used to fund that responsibility. Administrative functions can also be delegated without transferring healthcare-cost risk.

Does every delegated arrangement use a DOFR?

Not necessarily under that name or format. Financial responsibility may appear in a DOFR, risk matrix, responsibility schedule, contract exhibit, benefit grid, or several related documents.

Can an MSO accept delegated risk?

An MSO is not automatically risk bearing. Whether a particular MSO accepts risk depends on its legal structure, contracts, regulatory status, and actual allocation of financial responsibility.

Is delegated risk the same as an ACO arrangement?

No. Some ACO models involve upside and downside financial risk, but they do not automatically involve health-plan delegation, capitation, or DOFRs. The governing program and contracts determine the structure.

How often should delegated arrangements be reviewed?

Review should occur when relevant contracts, amendments, benefits, products, codes, vendors, systems, or regulatory requirements change. Periodic verification should supplement event-based review. No universal annual or quarterly schedule fits every arrangement.

19. Sources and Methodology

This guide combines primary regulatory sources, public program materials, public DOFR examples, and practitioner-reviewed operational knowledge. It describes common structures rather than prescribing one universal model.

Primary sources

Written by: Michael Riley, Co-Founder and Chief Product Officer of Gabeo.ai

Reviewed for operational accuracy by: Octavio Campos, Director of Operations at Guidant Health, with more than 20 years of DOFR experience

Last substantively reviewed: August 27, 2026

This material is educational. Financial responsibility, delegation, payment, coverage, and oversight depend on applicable requirements, member benefits, governing agreements, amendments, and current operational configuration.

20. Continue Learning

21. How ARIA Supports DOFR Accuracy

Delegated-risk operations depend on alignment among contracts, DOFRs, system rules, and claim outcomes.

ARIA helps health plans, IPAs, MSOs, and other delegated-risk organizations codify financial-responsibility terms and evaluate claims for potential responsibility mismatches. It is designed to support contract-to-claim analysis across complex service categories, amendments, and payer arrangements while preserving the evidence needed for operational review.

ARIA complements existing claims platforms and human decision-making. Confirmed findings, remediation, recovery, and prospective configuration changes remain subject to the governing contract and the organization's validation and dispute processes.

To learn more, explore ARIA for delegated risk.