How to Prepare for a Medicare/Medicaid Audit: A Practice Manager's Survival Guide
An audit notice from a Medicare contractor rarely arrives at
a convenient time, and the acronym on the letterhead matters more than most
practice owners realize. Whether the notice comes from a MAC, a RAC, a UPIC, or
the CERT program, the type of contractor determines the seriousness of
the review, the documentation expected, and the timeline for response. This
guide breaks down the alphabet soup of CMS audit contractors, explains what
typically triggers each type of review, and outlines how a practice can move
from reactive scrambling to a proactive and "audit-ready" posture.
The Alphabet Soup: Types of Medicare and Medicaid Audits Explained
CMS relies on a network of contractors to monitor billing
accuracy and program integrity across Medicare and Medicaid. Each contractor
has a distinct purpose and focus when it comes to monitoring and auditing. Understanding which contractor sent the
letter is the first step in calibrating an appropriate response. Why? Because the stakes and process differ
substantially from one audit type to the next.
Targeted Probe and Educate (TPE)[1]
is run by Medicare Administrative Contractors (MACs) and is explicitly designed
to be educational rather than punitive. CMS describes TPE audit as a
program to assist providers and suppliers alike to reduce their claim denials
and appeals through "one-on-one" help. The focus of this audit is typically on
specific items or services with high denial rates, high error rates, or unusual
billing patterns compared to similar organizations. TPE reviews unfold in up to
three rounds of 20-40 claims each. After
each round, the MAC provides individualized education and those providers with
low error rates or demonstrated improvement can be removed from the review
process. However, continuous high error
rates can lead to escalated actions, including referral to a Recovery Auditor
or other CMS program integrity contractor.cms+1
Recovery Audit Contractors (RACs)[2]
operate under CMS's Medicare Fee-for-Service Recovery Audit Program. The
purpose of this program is to identify and correct improper Medicare
payments by conducting post-payment reviews. RACs conduct both automated
reviews of claims data and complex reviews that require medical record
documentation. They are compensated on a
contingency fee based on the improper payments they identify and collect. RAC
review topics must first be approved by CMS and posted publicly which
can give practices advanced notice of which billing issues are under national
scrutiny. Think of this as a way for your organization to get ahead of an audit
by conducting your own internal audit first.
CMS is practically giving you the answers to the test in advance!
Comprehensive Error Rate Testing (CERT)[3]
is fundamentally different in purpose. It is not an enforcement audit but a
measurement program. Each year the CERT program reviews a statistically
valid random sample of Medicare FFS claims. Using that data, they determine if
they were paid properly. This ultimately produces the national Medicare
Fee-for-Service improper payment rate. A CERT documentation request means a
claim was randomly selected as part of this national sampling exercise, not
that the practice has been flagged for suspected wrongdoing. However, an
overpayment identified in a CERT audit still must be repaid.
Unified Program Integrity Contractors (UPICs)[4]
represent the highest risk category of audit. A UPIC audit is performed
for fraud, waste, and abuse detection, deterrence and prevention activities
for Medicare and Medicaid across their assigned jurisdictions. They are directed
to investigate allegations of fraud whether they are made by beneficiaries,
providers, suppliers, or other referral sources. Depending on the findings, it can result in
payment suspension, referrals to law enforcement, or civil and criminal action.
A UPIC review spans both Medicare and Medicaid claims and can often signal a
fraud investigation rather than a payment-accuracy check. Suffice it to say, if
you receive a UPIC audit notification, it should be handled cautiously and with
a legally supported response.
Supplemental Medical Review Contractors (SMRCs)[5]
conduct reviews on specific issues decided by the CMS rather than
by a MAC's local error-rate findings. SMRC audits consist of a nationwide
medical claims review of Medicaid, Medicare Part A/B, and DMEPOS claims.
Ultimately, it determines whether claims submitted are following coverage,
coding, payment, and established billing practices. These audits are typically
driven by data analysis, professional organization concerns, or congressional
inquiries about a specific service, item, or diagnosis code at a national level,
rather than by a single provider's individual billing history.
This chart is a simple way to understand the different types of CMS audits and what
triggers them.
|
Audit Type |
Contractor |
Primary Purpose |
Risk Level |
Typical Trigger |
|
TPE |
MAC |
Education, reduce denials |
Low-Moderate |
Peer-benchmark outliers, high denial rates |
|
RAC |
Recovery Audit Contractor |
Recover post-payment overpayments |
Moderate-High |
CMS-approved review topics, billing anomalies |
|
CERT |
CERT contractor |
Measure national improper payment rate |
Low (random) |
Statistically random claim sample |
|
UPIC |
Unified Program Integrity Contractor |
Fraud, waste, and abuse investigation |
High |
Complaints, referrals, suspected fraud patterns |
|
SMRC |
Supplemental Medical Review Contractor |
CMS-directed issue-specific review |
Moderate |
National data trends on a specific service/code |
What Triggers Each Type of Audit
Now that you have a basic understanding of the types of
audits that occur, let's dive more into how one of these audits is triggered.
Audit selection is increasingly data-driven rather than
random. CMS and its program integrity partners rely on predictive analytics and
data mining to flag providers with billing patterns that diverge from those of statistically
similar peers. This is a practice
formalized through CMS's Fraud Prevention System and related
predictive-analytics technologies. The Department of Health and Human Services
(HHS) Office of Inspector General (OIG) has repeatedly examined how these
fraud-detection models are governed. CMS uses a structured process to create or
adapt their fraud-detection models to address "identified vulnerabilities"
from prior OIG work.
Looking at TPE audits, MACs will select providers and
suppliers based on documented risk indicators.
Typically, these indicators include high claim denial rates, unusual
billing patterns relative to peers, and items or services with high national
error rates or vulnerability to improper payments. In contrast, RAC audits
review topics formally proposed and approved by CMS before a RAC can begin pursuing
organizations. The current list[6]
of approved topics is published so providers can anticipate likely areas of
scrutiny. UPIC audits frequently open investigations based on complaints
from beneficiaries or providers, referrals from other contractors (including
MACs that saw high TPE error rates), or their own data analysis of billing
patterns across both Medicare and Medicaid claims.
CERT audit selections remain purely random by
statistical design, which is the one category unimpacted by a provider's
individual billing behavior. SMRC audits are typically initiated at
CMS's direction in response to national-level data trends, coverage policy
questions, or stakeholder concerns about a specific benefit category.
What to Do the Moment You Receive an Audit Notice
The moment has come.
You get the dreaded audit letter. First things first—DON'T PANIC! Yes,
audits can be very unnerving but how you respond to the request can have
a significant impact on your entire organization, even down to the line employees.
The first few days after an audit letter arrives, the tone
for the entire response. Any request for medical records, tied to a Medicare
claim review, is generally referred to as an Additional Documentation
Request (ADR)[7],
and CMS guidance is explicit that documentation is due within 45 calendar
days of the request date for MAC, SMRC, and RAC reviews, though the
contractor may accept late documentation "for good cause". Missing
that window without a valid explanation can result in the claim being
treated as if no documentation exists at all, which typically means automatic
denial and repayment.
Three actions should happen within the first 24-48 hours of
receiving any audit notice:
1. Identify precisely which contractor sent the
letter and what type of audit it represents
2. Calendar the response deadline immediately and
work backwards from the 45-day (or other due date) requirement to build in
internal review time. Include a buffer
for mailing or portal submission delays and responses from legal counsel (if
appropriate).
3. Designate a single point of contact (such as a
compliance officer or billing manager) who will coordinate document gathering,
track correspondence, and serve as the practice's consistent voice with the
contractor throughout the process.
It is also worth confirming whether the request falls within
CMS's documentation request limits. Recovery Auditors are typically capped at
how many records they may request within a rolling 45-day period. This number
is based on the provider's claim volume. A reasonable floor of 20 records per
45 days is standard for smaller organizations. Organizations facing an
unusually large or repeated ADR volume should verify the request against the
published limits before assuming full compliance is required.
How to Respond to Each Audit Type
Your response strategy should track the audit type
identified previously in this post. TPE, RAC, and UPIC audits all call for
different levels of engagement and caution. Here's a breakdown:
For a TPE audits, the most productive posture is active
participation in the educational process itself. CMS designed TPE so that
providers receive individualized feedback after each round of
20-40 claims. Those who demonstrate low error rates or genuine improvement can
exit the review without proceeding to further rounds. This is where you want to
be in a TPE audit. Because the program
is structured to reward correction, practices should treat the one-on-one
education sessions as an opportunity to fix systemic documentation gaps
before the second or third round, rather than as an adversarial proceeding.
For a RAC audits, speed and organization in
gathering documentation matter most. Remember, RAC audits operate on defined
ADR limits and deadlines and are financially incentivized to identify
improper payments. If a RAC determination results in a negative finding,
providers retain the right to pursue Medicare's five-level appeals process.
Here's a quick review and breakdown:
1.
Redetermination by the MAC
2.
Reconsideration
3.
Proceeding through Administrative Law Judge
hearing
4.
Medicare Appeals Council review and Federal District
Court
Appeal deadlines and evidentiary requirements are specific
to each level and knowing that the pathway exists without attempting to
navigate its legal nuances internally, is the appropriate scope of general
audit preparedness.
A UPIC notice should be treated with the highest
degree of seriousness the moment it arrives. Remember, UPIC audits exist specifically to detect and
deter fraud, waste, and abuse, across both Medicare and Medicaid. Since UPIC
findings can lead to payment suspension or referral for further investigation,
involving compliance leadership and legal counsel promptly is essential. Legal
counsel should especially review all documentation before submission. This
gives your organization the best chance to respond in a coordinated and legally
sound manner.
The Cost of Getting It Wrong
The financial exposure from a mishandled audit often extends
beyond the specific claims reviewed. When a sample of claims is found to
contain errors, the CMS Program Integrity Manual guidance allows contractors to
use "extrapolation methods", such as projection, extension, or expansion
of known data to determine the overpayment amounts to be recovered. In plain
English, this means an error rate found in a small sample can be applied
mathematically across the practice's entire universe of similar claims. This
extrapolation methodology (along with the sampling approach used to calculate
it) can itself be challenged during an appeal. The CMS' guidance also addresses
circumstances when a sampling methodology can be overturned.
Beyond extrapolated repayment demands, escalation is a real
consequence of continued noncompliance. A provider who fails to show
improvement across TPE's rounds of review can be referred to as a Recovery
Auditor or another CMS program integrity contractor for further action. If high
error rates continue, it can lead to 100 percent prepayment review of future
claims. In the most serious cases, particularly those beginning as UPIC
investigations, findings can be referred to as civil or criminal investigation
under the Medicaid Program Integrity framework. Each of these escalation paths
reinforces why a proactive, well-documented compliance program is
far less costly than reacting after a pattern of errors has already been
established.
Building an "Always Audit-Ready" Practice
The strongest defense against any of these audits is a
practice culture built around continuous documentation quality. Even the CMS
emphasizes the TPE reviews are meant to reduce claim denials on an ongoing
basis. Provider education through TPE
audits is a phenomenal way to help providers build positive habits. This is precisely what a practice should be
reinforcing on a routine basis anyway, before any external contractor ever gets
involved.
Routine internal chart audits, conducted with the same rigor
as any CMS audit allows your organization to catch documentation gaps, missing
signatures, or medical-necessity shortfalls long before they surface in an
external review. Monitoring and Auditing is one of the fundamental elements of
an effective compliance program and ensuring accuracy is one of the main
reasons why. Documentation training
should be tied directly to real audit findings and coverage requirements, since
CMS's TPE education sessions are specifically structured around the gaps
identified in each provider's own claims, rather than generic guidance.
Finally, maintaining a defensible audit trail, such as showing who reviewed
each chart, when the review occurred, and what corrective action followed,
gives a practice the documentation needed to demonstrate a good-faith
compliance effort if a dispute over sampling methodology or extrapolation ever
arises during an appeal.
So, how does HCP help?
HCP's audit support and chart analytics and auditing service
line brings together a dedicated and certified coding, and compliance team that
can help your organization. We can look prospectively or retroactively at
claims data to determine if your providers are falling outside of federal,
state, and in-practice norms. We can help interpret which type of audit
notice is received, organize documentation gathering against the 45-day ADR
deadline, and coordinate the response across all healthcare regulatory
compliance areas simultaneously. Rather than treating an audit letter as an
isolated crisis, this coordinated approach connects the specific review to the
practice's broader compliance program. Then, using the lessons learned during
one audit, strengthen the practice's readiness for the next.
Conclusion and Next Steps
Every Medicare and Medicaid audit contractor serves a
different function and confusing them or missing the response window are among
the costliest mistakes a practice can make.
The most reliable protection against any of these audit types is a documentation and training program that operates continuously, not one built only after a letter arrives. Practices ready to assess how their current documentation, coding, and compliance protocols would hold up against a TPE, RAC, or UPIC review should schedule an audit-readiness assessment to identify gaps…before CMS does.
[1] https://www.cms.gov/data-research/monitoring-programs/medicare-fee-service-compliance-programs/medical-review-and-education/targeted-probe-and-educate-tpe
[2] https://www.cms.gov/data-research/monitoring-programs/medicare-fee-service-compliance-programs/medicare-fee-service-recovery-audit-program
[3] https://www.cms.gov/data-research/monitoring-programs/improper-payment-measurement-programs/comprehensive-error-rate-testing-cert
[4] https://www.cms.gov/data-research/monitoring-programs/medicare-fee-service-compliance-programs/review-contractor-directory-interactive-map
[5] https://www.cms.gov/data-research/monitoring-programs/medicare-fee-service-compliance-programs/medical-review-and-education/supplemental-medical-review-contractor-smrc
[6] https://www.cms.gov/data-research/monitoring-programs/medicare-fee-service-compliance-programs/medicare-fee-service-recovery-audit-program/approved-rac-topics
[7] https://www.cms.gov/data-research/monitoring-programs/medicare-fee-service-compliance-programs/medical-review-education/additional-documentation-request