Desk setup showing a Medicare/Medicaid audit guide with checklist, binders labeled audit prep and documentation, notes, and charts.

How to Prepare for a Medicare/Medicaid Audit: A Practice Manager’s Survival Guide

How to Prepare for a Medicare/Medicaid Audit: A Practice Manager's Survival Guide

An audit notice from a Medicare contractor rarely arrives at a convenient time, and the acronym on the letterhead matters more than most practice owners realize. Whether the notice comes from a MAC, a RAC, a UPIC, or the CERT program, the type of contractor determines the seriousness of the review, the documentation expected, and the timeline for response. This guide breaks down the alphabet soup of CMS audit contractors, explains what typically triggers each type of review, and outlines how a practice can move from reactive scrambling to a proactive and "audit-ready" posture.

The Alphabet Soup: Types of Medicare and Medicaid Audits Explained

CMS relies on a network of contractors to monitor billing accuracy and program integrity across Medicare and Medicaid. Each contractor has a distinct purpose and focus when it comes to monitoring and auditing. Understanding which contractor sent the letter is the first step in calibrating an appropriate response. Why? Because the stakes and process differ substantially from one audit type to the next.

Targeted Probe and Educate (TPE)[1] is run by Medicare Administrative Contractors (MACs) and is explicitly designed to be educational rather than punitive. CMS describes TPE audit as a program to assist providers and suppliers alike to reduce their claim denials and appeals through "one-on-one" help. The focus of this audit is typically on specific items or services with high denial rates, high error rates, or unusual billing patterns compared to similar organizations. TPE reviews unfold in up to three rounds of 20-40 claims each. After each round, the MAC provides individualized education and those providers with low error rates or demonstrated improvement can be removed from the review process. However, continuous high error rates can lead to escalated actions, including referral to a Recovery Auditor or other CMS program integrity contractor.cms+1

Recovery Audit Contractors (RACs)[2] operate under CMS's Medicare Fee-for-Service Recovery Audit Program. The purpose of this program is to identify and correct improper Medicare payments by conducting post-payment reviews. RACs conduct both automated reviews of claims data and complex reviews that require medical record documentation. They are compensated on a contingency fee based on the improper payments they identify and collect. RAC review topics must first be approved by CMS and posted publicly which can give practices advanced notice of which billing issues are under national scrutiny. Think of this as a way for your organization to get ahead of an audit by conducting your own internal audit first. CMS is practically giving you the answers to the test in advance!

Comprehensive Error Rate Testing (CERT)[3] is fundamentally different in purpose. It is not an enforcement audit but a measurement program. Each year the CERT program reviews a statistically valid random sample of Medicare FFS claims. Using that data, they determine if they were paid properly. This ultimately produces the national Medicare Fee-for-Service improper payment rate. A CERT documentation request means a claim was randomly selected as part of this national sampling exercise, not that the practice has been flagged for suspected wrongdoing. However, an overpayment identified in a CERT audit still must be repaid.

Unified Program Integrity Contractors (UPICs)[4] represent the highest risk category of audit. A UPIC audit is performed for fraud, waste, and abuse detection, deterrence and prevention activities for Medicare and Medicaid across their assigned jurisdictions. They are directed to investigate allegations of fraud whether they are made by beneficiaries, providers, suppliers, or other referral sources. Depending on the findings, it can result in payment suspension, referrals to law enforcement, or civil and criminal action. A UPIC review spans both Medicare and Medicaid claims and can often signal a fraud investigation rather than a payment-accuracy check. Suffice it to say, if you receive a UPIC audit notification, it should be handled cautiously and with a legally supported response.

Supplemental Medical Review Contractors (SMRCs)[5] conduct reviews on specific issues decided by the CMS rather than by a MAC's local error-rate findings. SMRC audits consist of a nationwide medical claims review of Medicaid, Medicare Part A/B, and DMEPOS claims. Ultimately, it determines whether claims submitted are following coverage, coding, payment, and established billing practices. These audits are typically driven by data analysis, professional organization concerns, or congressional inquiries about a specific service, item, or diagnosis code at a national level, rather than by a single provider's individual billing history.

This chart is a simple way to understand the different types of CMS audits and what triggers them.

Audit Type

Contractor

Primary Purpose

Risk Level

Typical Trigger

TPE

MAC

Education, reduce denials

Low-Moderate

Peer-benchmark outliers, high denial rates

RAC

Recovery Audit Contractor

Recover post-payment overpayments

Moderate-High

CMS-approved review topics, billing anomalies

CERT

CERT contractor

Measure national improper payment rate

Low (random)

Statistically random claim sample

UPIC

Unified Program Integrity Contractor

Fraud, waste, and abuse investigation

High

Complaints, referrals, suspected fraud patterns

SMRC

Supplemental Medical Review Contractor

CMS-directed issue-specific review

Moderate

National data trends on a specific service/code

What Triggers Each Type of Audit

Now that you have a basic understanding of the types of audits that occur, let's dive more into how one of these audits is triggered.

Audit selection is increasingly data-driven rather than random. CMS and its program integrity partners rely on predictive analytics and data mining to flag providers with billing patterns that diverge from those of statistically similar peers. This is a practice formalized through CMS's Fraud Prevention System and related predictive-analytics technologies. The Department of Health and Human Services (HHS) Office of Inspector General (OIG) has repeatedly examined how these fraud-detection models are governed. CMS uses a structured process to create or adapt their fraud-detection models to address "identified vulnerabilities" from prior OIG work.

Looking at TPE audits, MACs will select providers and suppliers based on documented risk indicators. Typically, these indicators include high claim denial rates, unusual billing patterns relative to peers, and items or services with high national error rates or vulnerability to improper payments. In contrast, RAC audits review topics formally proposed and approved by CMS before a RAC can begin pursuing organizations. The current list[6] of approved topics is published so providers can anticipate likely areas of scrutiny. UPIC audits frequently open investigations based on complaints from beneficiaries or providers, referrals from other contractors (including MACs that saw high TPE error rates), or their own data analysis of billing patterns across both Medicare and Medicaid claims.

CERT audit selections remain purely random by statistical design, which is the one category unimpacted by a provider's individual billing behavior. SMRC audits are typically initiated at CMS's direction in response to national-level data trends, coverage policy questions, or stakeholder concerns about a specific benefit category.

What to Do the Moment You Receive an Audit Notice

The moment has come. You get the dreaded audit letter. First things first—DON'T PANIC! Yes, audits can be very unnerving but how you respond to the request can have a significant impact on your entire organization, even down to the line employees.

The first few days after an audit letter arrives, the tone for the entire response. Any request for medical records, tied to a Medicare claim review, is generally referred to as an Additional Documentation Request (ADR)[7], and CMS guidance is explicit that documentation is due within 45 calendar days of the request date for MAC, SMRC, and RAC reviews, though the contractor may accept late documentation "for good cause". Missing that window without a valid explanation can result in the claim being treated as if no documentation exists at all, which typically means automatic denial and repayment.

Three actions should happen within the first 24-48 hours of receiving any audit notice:

1. Identify precisely which contractor sent the letter and what type of audit it represents

2. Calendar the response deadline immediately and work backwards from the 45-day (or other due date) requirement to build in internal review time. Include a buffer for mailing or portal submission delays and responses from legal counsel (if appropriate).

3. Designate a single point of contact (such as a compliance officer or billing manager) who will coordinate document gathering, track correspondence, and serve as the practice's consistent voice with the contractor throughout the process.

It is also worth confirming whether the request falls within CMS's documentation request limits. Recovery Auditors are typically capped at how many records they may request within a rolling 45-day period. This number is based on the provider's claim volume. A reasonable floor of 20 records per 45 days is standard for smaller organizations. Organizations facing an unusually large or repeated ADR volume should verify the request against the published limits before assuming full compliance is required.

How to Respond to Each Audit Type

Your response strategy should track the audit type identified previously in this post. TPE, RAC, and UPIC audits all call for different levels of engagement and caution. Here's a breakdown:

For a TPE audits, the most productive posture is active participation in the educational process itself. CMS designed TPE so that providers receive individualized feedback after each round of 20-40 claims. Those who demonstrate low error rates or genuine improvement can exit the review without proceeding to further rounds. This is where you want to be in a TPE audit. Because the program is structured to reward correction, practices should treat the one-on-one education sessions as an opportunity to fix systemic documentation gaps before the second or third round, rather than as an adversarial proceeding.

For a RAC audits, speed and organization in gathering documentation matter most. Remember, RAC audits operate on defined ADR limits and deadlines and are financially incentivized to identify improper payments. If a RAC determination results in a negative finding, providers retain the right to pursue Medicare's five-level appeals process. Here's a quick review and breakdown:

1. Redetermination by the MAC

2. Reconsideration

3. Proceeding through Administrative Law Judge hearing

4. Medicare Appeals Council review and Federal District Court

Appeal deadlines and evidentiary requirements are specific to each level and knowing that the pathway exists without attempting to navigate its legal nuances internally, is the appropriate scope of general audit preparedness.

A UPIC notice should be treated with the highest degree of seriousness the moment it arrives. Remember, UPIC audits exist specifically to detect and deter fraud, waste, and abuse, across both Medicare and Medicaid. Since UPIC findings can lead to payment suspension or referral for further investigation, involving compliance leadership and legal counsel promptly is essential. Legal counsel should especially review all documentation before submission. This gives your organization the best chance to respond in a coordinated and legally sound manner.

The Cost of Getting It Wrong

The financial exposure from a mishandled audit often extends beyond the specific claims reviewed. When a sample of claims is found to contain errors, the CMS Program Integrity Manual guidance allows contractors to use "extrapolation methods", such as projection, extension, or expansion of known data to determine the overpayment amounts to be recovered. In plain English, this means an error rate found in a small sample can be applied mathematically across the practice's entire universe of similar claims. This extrapolation methodology (along with the sampling approach used to calculate it) can itself be challenged during an appeal. The CMS' guidance also addresses circumstances when a sampling methodology can be overturned.

Beyond extrapolated repayment demands, escalation is a real consequence of continued noncompliance. A provider who fails to show improvement across TPE's rounds of review can be referred to as a Recovery Auditor or another CMS program integrity contractor for further action. If high error rates continue, it can lead to 100 percent prepayment review of future claims. In the most serious cases, particularly those beginning as UPIC investigations, findings can be referred to as civil or criminal investigation under the Medicaid Program Integrity framework. Each of these escalation paths reinforces why a proactive, well-documented compliance program is far less costly than reacting after a pattern of errors has already been established.

Building an "Always Audit-Ready" Practice

The strongest defense against any of these audits is a practice culture built around continuous documentation quality. Even the CMS emphasizes the TPE reviews are meant to reduce claim denials on an ongoing basis. Provider education through TPE audits is a phenomenal way to help providers build positive habits. This is precisely what a practice should be reinforcing on a routine basis anyway, before any external contractor ever gets involved.

Routine internal chart audits, conducted with the same rigor as any CMS audit allows your organization to catch documentation gaps, missing signatures, or medical-necessity shortfalls long before they surface in an external review. Monitoring and Auditing is one of the fundamental elements of an effective compliance program and ensuring accuracy is one of the main reasons why. Documentation training should be tied directly to real audit findings and coverage requirements, since CMS's TPE education sessions are specifically structured around the gaps identified in each provider's own claims, rather than generic guidance. Finally, maintaining a defensible audit trail, such as showing who reviewed each chart, when the review occurred, and what corrective action followed, gives a practice the documentation needed to demonstrate a good-faith compliance effort if a dispute over sampling methodology or extrapolation ever arises during an appeal.

So, how does HCP help?

HCP's audit support and chart analytics and auditing service line brings together a dedicated and certified coding, and compliance team that can help your organization. We can look prospectively or retroactively at claims data to determine if your providers are falling outside of federal, state, and in-practice norms. We can help interpret which type of audit notice is received, organize documentation gathering against the 45-day ADR deadline, and coordinate the response across all healthcare regulatory compliance areas simultaneously. Rather than treating an audit letter as an isolated crisis, this coordinated approach connects the specific review to the practice's broader compliance program. Then, using the lessons learned during one audit, strengthen the practice's readiness for the next.

Conclusion and Next Steps

Every Medicare and Medicaid audit contractor serves a different function and confusing them or missing the response window are among the costliest mistakes a practice can make.

The most reliable protection against any of these audit types is a documentation and training program that operates continuously, not one built only after a letter arrives. Practices ready to assess how their current documentation, coding, and compliance protocols would hold up against a TPE, RAC, or UPIC review should schedule an audit-readiness assessment to identify gaps…before CMS does.


[1] https://www.cms.gov/data-research/monitoring-programs/medicare-fee-service-compliance-programs/medical-review-and-education/targeted-probe-and-educate-tpe

[2] https://www.cms.gov/data-research/monitoring-programs/medicare-fee-service-compliance-programs/medicare-fee-service-recovery-audit-program

[3] https://www.cms.gov/data-research/monitoring-programs/improper-payment-measurement-programs/comprehensive-error-rate-testing-cert

[4] https://www.cms.gov/data-research/monitoring-programs/medicare-fee-service-compliance-programs/review-contractor-directory-interactive-map

[5] https://www.cms.gov/data-research/monitoring-programs/medicare-fee-service-compliance-programs/medical-review-and-education/supplemental-medical-review-contractor-smrc

[6] https://www.cms.gov/data-research/monitoring-programs/medicare-fee-service-compliance-programs/medicare-fee-service-recovery-audit-program/approved-rac-topics

[7] https://www.cms.gov/data-research/monitoring-programs/medicare-fee-service-compliance-programs/medical-review-education/additional-documentation-request