July 7, 2026
The 7 Types of Medicare Audits Explained: RAC, MAC, UPIC, CERT, SMRC, TPE, and OIG
- by Gene Good, JD, CEO
How to Identify Which Contractor Is Reviewing Your Claims, What Authority It Holds, and What Your Practice Is Actually Facing
Table of Contents
- Introduction: The First Question Is Not What You Billed, It Is Who Is Asking
- Why Contractor Identity Determines Your Exposure
- Audit Type 1: Medicare Administrative Contractors (MACs)
- Audit Type 2: Targeted Probe and Educate (TPE)
- Audit Type 3: Recovery Audit Contractors (RACs)
- Audit Type 4: Unified Program Integrity Contractors (UPICs)
- Audit Type 5: Supplemental Medical Review Contractor (SMRC)
- Audit Type 6: Comprehensive Error Rate Testing (CERT)
- Audit Type 7: HHS Office of Inspector General (OIG)
- Side-by-Side Comparison: Deadlines, Look-Back Periods, and Authority
- What Triggers Each Type of Audit
- Extrapolation: The Factor That Changes Everything
- How One Audit Becomes Another: Escalation Pathways
- Reading Your Audit Letter: A Practical Identification Guide
- The First Five Actions After an Audit Letter Arrives
- How DoctorsManagement Defends Practices Across Every Audit Type
- Frequently Asked Questions
- External Resources and References
Introduction: The First Question Is Not What You Billed, It Is Who Is Asking
When an audit letter arrives at a medical practice, the instinctive response is to start pulling charts. That instinct is understandable and it is also premature. Before a single record is retrieved, someone in the practice needs to answer a more consequential question: which contractor sent this letter, and what authority does that contractor actually have?
The answer determines almost everything that follows. It determines how many days you have to respond, whether that deadline is 30 or 45. It determines whether the reviewer is looking at claims already paid or holding future payments hostage. It determines whether the worst realistic outcome is a modest repayment demand or a seven-figure extrapolated liability. And it determines whether you are dealing with a routine payment-integrity review or the front end of a fraud investigation that may be referred to the Department of Justice.
Medicare program integrity work is distributed across a set of contractors with genuinely different mandates. A Medicare Administrative Contractor conducting a routine prepayment review and a Unified Program Integrity Contractor investigating suspected fraud will both send you a request for medical records. The letters look similar. The consequences are not remotely similar. Practices that treat every records request the same way routinely underreact to the dangerous ones and overreact to the routine ones.
This guide maps all seven audit types a physician practice is likely to encounter. For each, it covers who the contractor is, what authority it holds, what triggers its interest, how long you have to respond, how far back it can look, whether it can extrapolate, and what the realistic downside looks like. It closes with a practical guide to identifying which audit you are facing from the letter itself, and the first five actions to take once you know.
Why Contractor Identity Determines Your Exposure
Four variables separate a manageable audit from a practice-threatening one. Each of them is a function of which contractor is involved.
Response Deadline
Most contractors allow 45 calendar days to produce records. UPICs allow 30. That fifteen-day difference matters enormously when the request covers dozens of claims across multiple years and the records live in more than one system. Practices that assume they have 45 days when they actually have 30 lose the case before it starts, because an unanswered documentation request is not a neutral event. It converts to a denial, and the denial converts to an overpayment.
Payment Posture
Prepayment review means claims are held before payment. Cash flow stops immediately and stays stopped for the duration of the review. Post-payment review means the contractor is examining money you have already received and spent, and will demand it back. Both are serious. They are serious in completely different ways, and they call for different operational responses.
Extrapolation Authority
Some contractors may project the error rate found in a small sample across the entire universe of comparable claims. This is the single largest driver of catastrophic audit exposure. An error rate of eleven percent found in a forty-claim sample can become a demand measured in seven figures once projected across three years of billing. Whether the contractor reviewing your claims has this authority is the most financially significant question in the entire process.
Enforcement Referral Risk
Most contractors are looking for improper payments. UPICs and the OIG are looking for fraud. A UPIC can conduct unannounced site visits, interview staff, suspend payments, and refer a matter to the OIG or the Department of Justice. When that contractor is involved, the exposure is not merely financial and the response should involve counsel from the outset.
Audit Type 1: Medicare Administrative Contractors (MACs)
MACs are the regional contractors that process Medicare fee-for-service claims. Your practice already interacts with a MAC constantly, because the MAC is who you bill. Beyond claims processing, MACs conduct medical review to ensure claims meet coverage, coding, and documentation requirements.
Authority and Scope
MACs conduct both prepayment and post-payment review within their jurisdiction. Prepayment review is the more operationally disruptive of the two, because claims subject to review are held before payment rather than paid and later recovered. A practice placed on prepayment review experiences an immediate interruption in cash flow that continues until the review is lifted.
Response Deadline
45 calendar days from the date printed on the additional documentation request. The regulatory basis is 42 CFR 405.903 for prepayment review and 42 CFR 405.929 for post-payment review.
Typical Triggers
- A claim trips a service-specific edit or fails an automated coverage check
- Billing patterns that deviate from local coverage determination expectations
- Selection for a targeted probe based on error-rate data
- A referral downstream from another contractor’s findings
Realistic Exposure
For a limited prepayment review, exposure is primarily operational: delayed payment on the claims under review and the administrative cost of responding. For a broader post-payment review, exposure is the value of denied claims plus the risk that findings escalate to a larger review. MACs also administer the demand and recoupment process for findings generated by other contractors, so the MAC is frequently the entity that ultimately sends the bill even when it did not conduct the review.
Audit Type 2: Targeted Probe and Educate (TPE)
TPE is a MAC-administered program, but it functions distinctly enough to warrant separate treatment. It is also the audit a typical physician practice is most likely to encounter, and the one most commonly mishandled.
How TPE Works
TPE is structured as an educational intervention rather than a pure recovery action. The MAC selects a small sample of claims, generally twenty to forty, reviews them, and then offers one-on-one education addressing the errors found. The practice then has a correction window of roughly 45 days before the next round begins.
The program runs up to three rounds. A practice that demonstrates sufficient improvement can exit after Round 1 or Round 2 and return to normal claims processing. A practice that does not improve proceeds to the next round.
Why Round 3 Matters So Much
Failure to achieve compliance after three rounds is the point at which TPE stops being educational. CMS may then refer the practice for 100 percent prepayment review, authorize extrapolation, refer the matter to a Recovery Audit Contractor, or pursue other administrative action. Any of these outcomes is materially worse than the TPE itself.
This structure creates an unusual dynamic. TPE is simultaneously the most forgiving audit in the Medicare program and the gateway to the least forgiving ones. The practices that fare worst are those that treat Round 1 as a formality, submit records without reviewing them, and discover in Round 2 that the same documentation deficiencies are still present.
Response Deadline
45 calendar days for the documentation request, followed by a correction period of approximately 45 days between rounds.
The Strategic Insight
The correction window between rounds is the most valuable and most underused asset in the entire TPE process. It exists specifically so the practice can fix what the MAC identified. Practices that use it to conduct an internal audit of the same service line, retrain the providers responsible for the deficient documentation, and verify the fix before the next round begins routinely exit at Round 2. Practices that treat the education session as a box to check tend to see Round 3.
Audit Type 3: Recovery Audit Contractors (RACs)
RACs are the contractors most providers have heard of, and their defining feature is their compensation structure.
The Contingency Fee Structure
RACs are paid a percentage of what they recover. This is not a criticism of individual reviewers so much as a structural fact that providers should understand: the program is designed to find overpayments, and the entity conducting the review has a direct financial interest in finding them. That structure informs how findings should be scrutinized and how readily they should be accepted.
Look-Back Period and Documentation Limits
RAC review volume is governed by additional documentation request limits tied to the provider’s claim volume. The baseline annual ADR limit is calculated as a percentage of the provider’s total paid Medicare claims from the prior twelve-month period, and that annual figure is divided into eight cycles, establishing the maximum number of claims that can be requested in any single 45-day period. RACs may not issue requests more frequently than every 45 days.
The look-back period is linked to which limit the RAC elects to use. A RAC reviewing under the baseline annual ADR limit may look back three years from the claim paid date. A RAC reviewing under an adjusted ADR limit, which applies to providers with elevated denial rates, works from a shorter six-month look-back. Denial rates are recalculated after three 45-day cycles, and favorable appeal outcomes are factored into that recalculation.
Response Deadline
45 calendar days for the documentation request.
The Discussion Period
When a RAC notifies a provider of overpayment findings, a discussion period opens during which the provider may submit additional documentation and argue for reversal directly to the RAC, before the finding is referred to the MAC for recoupment. Each RAC administers its own discussion process and publishes the procedure on its website.
Two features of the discussion period are frequently misunderstood. First, it is not an appeal. Contacting the RAC does not preserve appeal rights, does not stop interest from accruing, and does not extend the deadline to request redetermination. Second, once a provider requests redetermination from the MAC, the discussion option closes. The two paths cannot be pursued simultaneously, which makes sequencing a genuine strategic decision rather than an administrative detail.
Extrapolation Authority
CMS permits Recovery Auditors to use extrapolation in defined circumstances, including providers who maintain a high denial rate over an extended period, providers with excessively high denial rates over a shorter period, and providers with a moderate denial rate whose improper payments nonetheless total a significantly high dollar amount. This is the mechanism by which a RAC review of forty claims becomes a demand across three years of billing.
Audit Type 4: Unified Program Integrity Contractors (UPICs)
A UPIC letter is the most serious routine correspondence a medical practice can receive from a Medicare contractor.
UPICs consolidated the functions of earlier program integrity contractors into single entities responsible for both Medicare and Medicaid across five regions. Their mandate is not payment accuracy. It is fraud, waste, and abuse.
Authority and Scope
UPICs are authorized to identify program vulnerabilities, proactively detect potential fraud within their service area, investigate allegations of fraud, develop fraud leads, initiate administrative actions including payment suspensions and enrollment revocations where reliable evidence of fraud exists, and refer providers for further action. They may conduct unannounced site visits and interview staff. They also review both pre-payment and post-payment.
Notably, UPICs are statutorily tasked with identifying underpayments as well as overpayments, a point that occasionally becomes relevant in defending against a one-sided review.
Response Deadline
30 calendar days, not 45. This is the shortest response window among the major contractors and the single most common deadline error practices make. A practice that calendars 45 days on a UPIC request has already lost fifteen days it did not have.
Realistic Exposure
Payment suspension, enrollment revocation, extrapolated overpayment demands, and referral to the OIG or Department of Justice. A UPIC investigation can develop into a False Claims Act matter. The financial exposure is real, but the enforcement exposure is what distinguishes a UPIC from every other contractor on this list.
Practical Guidance
When a UPIC letter arrives, engage healthcare counsel before responding, not after. The records submitted in response to a UPIC request may become evidence in a subsequent enforcement proceeding, and decisions about scope, privilege, and supplemental documentation should be made with that possibility in view. This is materially different from the posture appropriate to a routine MAC probe.
Audit Type 5: Supplemental Medical Review Contractor (SMRC)
The SMRC conducts nationwide medical review as directed by CMS, rather than operating within a geographic jurisdiction. Reviews cover Medicare Part A, Part B, and durable medical equipment, prosthetics, orthotics, and supplies.
How SMRC Reviews Are Selected
SMRC reviews are issue-driven rather than provider-driven. CMS identifies a service category or provider specialty presenting elevated improper payment risk, and the SMRC reviews claims in that category nationally. Selection inputs include CMS internal data analysis, CERT program findings, professional organization input, and recommendations from federal oversight agencies.
The practical implication is that an SMRC review is often not a judgment about your practice specifically. You may have been selected because you bill a service category that CMS has flagged nationally. That context is worth understanding, though it does not reduce the importance of the response.
Response Deadline
45 calendar days.
Realistic Exposure
Denial of reviewed claims and referral of findings to the MAC for recoupment. SMRC findings can also inform subsequent contractor activity, so a poor outcome may have downstream consequences beyond the claims at issue.
Audit Type 6: Comprehensive Error Rate Testing (CERT)
CERT is structurally different from every other audit on this list, and the difference is worth understanding because it changes the appropriate response.
Purpose
CERT exists to measure the national improper payment rate for the Medicare fee-for-service program. Claims are selected randomly. The program is a statistical measurement exercise, not a targeted enforcement action, and selection carries no implication that your billing was flagged.
Why It Still Matters
Two reasons. First, if the documentation you submit does not support the claim, the claim is still denied and the payment is still recovered. Random selection does not confer immunity. Second, and more significantly, CERT findings feed the national improper payment data that CMS uses to direct other contractors. A service category with a high CERT error rate becomes a target for SMRC review and RAC activity. Your individual CERT response contributes to that dataset.
Response Deadline
45 calendar days from the date of the letter.
The Most Common CERT Mistake
Practices frequently deprioritize CERT requests precisely because they are random and the individual dollar amounts are small. The result is incomplete submissions that generate insufficient-documentation denials. Those denials are recovered from the practice and they inflate the national error rate for that service, which invites further scrutiny of every practice billing it. A CERT request deserves the same documentation rigor as any other.
Audit Type 7: HHS Office of Inspector General (OIG)
The OIG is not a CMS contractor. It is the independent oversight arm of the Department of Health and Human Services, and its involvement signals a different category of matter entirely.
Authority and Scope
The OIG conducts audits, evaluations, and investigations of HHS programs. It holds subpoena power, coordinates with the Department of Justice on civil and criminal healthcare fraud enforcement, and administers program exclusion. It also publishes the annual Work Plan identifying the specific audit and enforcement priorities the agency intends to pursue, which is the closest thing providers have to advance notice of where federal attention is headed.
How OIG Involvement Typically Arises
- Referral from a UPIC or other contractor following a program integrity investigation
- A qui tam relator complaint filed under the False Claims Act
- Data analytics identifying billing patterns consistent with known fraud schemes
- A Work Plan initiative targeting the provider’s specialty or service line
- Voluntary self-disclosure by the provider through the OIG Self-Disclosure Protocol
Realistic Exposure
Civil monetary penalties, False Claims Act liability including treble damages and per-claim penalties, corporate integrity agreement obligations, program exclusion, and in cases involving criminal conduct, prosecution. This is not an audit in the sense that the other six are audits, and it should never be handled without experienced counsel.
Side-by-Side Comparison: Deadlines, Look-Back Periods, and Authority
The following summary consolidates the operative differences among the seven audit types.
Response Deadlines
- 30 calendar days: UPIC
- 45 calendar days: MAC, TPE, RAC, SMRC, CERT
- Varies by instrument: OIG, which may proceed by subpoena or civil investigative demand with its own timeline
Payment Posture
- Prepayment or post-payment: MAC, TPE, UPIC
- Post-payment: RAC, SMRC, CERT
- Investigative rather than claims-based: OIG
Extrapolation Authority
- Yes, under defined conditions: RAC, UPIC, and MACs following TPE failure
- Generally no: CERT, which measures rather than recovers at scale
- Uses statistical methods in a different posture: OIG, including within the Self-Disclosure Protocol damage calculation
Enforcement Referral Risk
- High: UPIC, OIG
- Moderate, generally through escalation: MAC following repeated TPE failure
- Lower, primarily financial: RAC, SMRC, CERT
What Triggers Each Type of Audit
Understanding what draws contractor attention allows a practice to monitor its own exposure before a letter arrives.
Data-Driven Triggers
- Billing volume for a specific code or modifier that places the provider in an outlier percentile relative to specialty peers
- Evaluation and management coding distribution skewed toward the highest levels
- Modifier 25 usage rates substantially above specialty norms
- Sudden changes in billing patterns, particularly volume increases in a single service line
- Referral or ordering patterns inconsistent with peer behavior
Event-Driven Triggers
- Prior contractor findings, since a RAC overpayment determination or CERT sample finding can produce a downstream review
- A qui tam complaint referred for billing analysis support
- Beneficiary or employee complaints
- Specialty-specific enforcement initiatives targeting a service category
- OIG Work Plan items covering the provider’s services
Random Selection
CERT alone selects randomly. Every other audit type on this list involves some form of targeting, whether provider-specific or service-category-specific. If you are facing anything other than a CERT review, something identified you.
Extrapolation: The Factor That Changes Everything
No other variable affects the financial magnitude of an audit as much as whether extrapolation is applied.
The mechanics are straightforward. The contractor reviews a sample of claims, calculates an error rate, and projects that rate across the full universe of comparable claims within the look-back period. A practice with 4,000 comparable claims over three years that shows a fifteen percent error rate in a forty-claim sample does not owe the value of six denied claims. It faces a demand calculated across roughly 600 projected claims.
What most providers do not know is that extrapolation methodology is challengeable, and that a successful challenge reduces liability to the actual overpayment identified in the sample rather than the projected amount. The difference is routinely the difference between a manageable repayment and an existential one.
Grounds for challenge include defects in how the universe of claims was defined, improper stratification, inadequate precision in the estimate, application of variable appraisal methodology to what are actually binary determinations, systematic bias where sample means exceed universe parameters, and misapplication of sampling software to highly skewed or low-variance claim populations.
An OIG review of the appeals process found that Medicare contractors were not consistent in how they reviewed extrapolated overpayments during provider appeals, and recommended that CMS provide additional guidance to improve consistency. That inconsistency is precisely why methodology challenges succeed with meaningful frequency, and why the Administrative Law Judge level of appeal is where extrapolation is most often defeated.
Challenging extrapolation requires statistical expertise, not merely coding expertise. This is a distinct discipline, and it is addressed in depth in the companion article in this series on statistical extrapolation in Medicare audits.
How One Audit Becomes Another: Escalation Pathways
Audits do not exist in isolation. Findings flow between contractors, and a small review handled poorly can produce a much larger one.
The Common Escalation Sequences
- TPE to prepayment review or RAC referral. Three failed TPE rounds can result in 100 percent prepayment review, authorized extrapolation, or referral to a Recovery Audit Contractor.
- CERT to SMRC. Elevated CERT error rates in a service category prompt CMS to direct nationwide SMRC review of that category.
- RAC to UPIC. A RAC overpayment determination showing a pattern rather than isolated errors can prompt program integrity referral.
- UPIC to OIG or DOJ. Where a UPIC develops reliable evidence of fraud, the matter moves from administrative recovery to enforcement.
- Any audit to False Claims Act exposure. Findings that establish the provider knew or should have known claims were improper, particularly where prior audit findings were not remediated, support the FCA knowledge standard.
The Remediation Point
The through-line in every escalation sequence is unremediated findings. A first audit that identifies a documentation deficiency is a problem. The same deficiency still present at the second audit is evidence. Practices that treat audit findings as a correction mandate rather than a cost of doing business break the escalation chain at its first link.
Reading Your Audit Letter: A Practical Identification Guide
Use the following to identify what you are facing within the first few minutes.
Check the Letterhead and Contractor Name
The contractor’s name appears on the letterhead. If it matches the MAC that processes your claims, you are dealing with MAC medical review or TPE. If it is a name you do not recognize, identify it before proceeding, since RACs, UPICs, and the SMRC operate under contractor names distinct from your MAC.
Look for Program Identification Language
- References to Targeted Probe and Educate, rounds, or an offer of one-on-one education indicate TPE
- References to the Recovery Audit Program or a discussion period indicate a RAC
- References to program integrity, investigation, or an unusually short response window indicate a UPIC
- References to a nationwide review of a specific service category indicate the SMRC
- References to measuring the improper payment rate indicate CERT
Note the Response Deadline
A 30-day window is a strong indicator of a UPIC. Calendar the deadline from the date printed on the letter, not the date it was received or opened.
Determine Prepayment or Post-Payment
Language indicating claims are being held pending review signals prepayment. Language referring to claims already paid, or an overpayment determination, signals post-payment.
Look for Extrapolation Language
References to statistical sampling, an overpayment estimate, a universe of claims, or a projected amount indicate extrapolation is in play. This changes the required response and generally warrants immediate expert involvement.
The First Five Actions After an Audit Letter Arrives
- Identify the contractor and calendar the deadline from the letter date. Confirm whether the window is 30 or 45 days. Build the internal schedule backward from the deadline with a submission target at least five business days early.
- Determine whether enforcement risk is present. If the letter is from a UPIC or the OIG, or if it references investigation rather than payment review, engage healthcare counsel before producing anything.
- Preserve everything. Implement a documentation hold covering the claims at issue and the surrounding period. Do not alter, append to, or reorganize records after receiving notice. Late additions to a record are among the most damaging findings an auditor can make.
- Audit the requested claims internally before submitting. Review each claim against the documentation as an auditor would. Knowing your own exposure before the contractor does determines whether you are managing the process or reacting to it.
- Decide on scope and supplemental documentation. Determine what the request actually requires, whether supporting records from other sources belong in the package, and whether a position paper explaining medical necessity should accompany the submission.
The mechanics of executing steps three through five are covered in detail in the companion article in this series on responding to a Medicare records request.
How DoctorsManagement Defends Practices Across Every Audit Type
DoctorsManagement has represented physician practices, group practices, health systems, ambulatory surgery centers, and federally qualified health centers through every category of Medicare and commercial payer audit. Our audit defense team combines credentialed coding and auditing expertise with statistical and economic analysis, which is the combination these matters actually require.
Our auditors hold both the Certified Professional Coder and Certified Professional Medical Auditor credentials and receive ongoing training through NAMAS, our education division. For matters involving extrapolation, we bring statisticians and economists who can evaluate sampling methodology on its own terms.
Our audit-related services include:
- Audit Response Management: Review of the documentation request, internal pre-submission audit of the claims at issue, and preparation of a complete, defensible response package
- Extrapolation Defense: Statistical analysis of contractor sampling methodology, identification of methodological defects, and expert support for challenges at every appeal level
- Appeal Representation: Preparation and prosecution of redetermination, reconsideration, and ALJ-level appeals, including medical necessity argumentation and clinical expert support
- Coding and Documentation Review: Independent assessment of coding accuracy and documentation sufficiency, both as audit defense and as remediation to prevent escalation
- Litigation Support and Expert Witness Services: Testifying expertise on coding, documentation, medical necessity, and statistical methodology where matters proceed to hearing or litigation
- Post-Audit Remediation: Corrective action planning, provider training, and compliance program strengthening to break the escalation chain
If your practice has received an audit letter, contact DoctorsManagement at www.doctorsmanagement.com/audit-appeal-defense or call (800) 635-4040. Early involvement produces materially better outcomes than engagement after findings are issued.
Frequently Asked Questions
How do I tell which type of Medicare audit I am facing?
Start with the contractor name on the letterhead and the response deadline. A 30-day window strongly suggests a UPIC. References to rounds and one-on-one education indicate TPE. References to the Recovery Audit Program or a discussion period indicate a RAC. Language about measuring the improper payment rate indicates CERT. A nationwide review of a specific service category indicates the SMRC.
How long do I have to respond to a Medicare records request?
45 calendar days for MAC, TPE, RAC, SMRC, and CERT requests, and 30 calendar days for UPIC requests. The clock runs from the date printed on the letter, not the date your practice received or opened it. Contractors may grant good cause extensions for documented extenuating circumstances, but the request must reach the contractor before the deadline passes.
Which audits can use extrapolation?
RACs may extrapolate under defined conditions involving elevated denial rates or significant improper payment dollar amounts. UPICs may extrapolate. MACs may extrapolate following TPE failure. CERT is a measurement program and does not extrapolate against individual providers in the same manner. Extrapolation is the single largest driver of catastrophic audit exposure, and its methodology is challengeable.
What is the difference between a RAC audit and a UPIC audit?
A RAC is a financial recovery program paid on contingency and focused on identifying improper payments. A UPIC is a program integrity contractor investigating fraud, waste, and abuse. UPICs can conduct unannounced site visits, interview staff, suspend payments, revoke enrollment, and refer matters to the OIG or Department of Justice. The RAC risk is primarily financial. The UPIC risk includes enforcement.
What happens if I fail all three rounds of TPE?
CMS may refer the practice for 100 percent prepayment review, authorize extrapolation, refer the matter to a Recovery Audit Contractor, or pursue other administrative action. Each of these outcomes is significantly worse than the TPE itself, which is why the correction window between rounds should be used for genuine internal auditing and provider retraining rather than treated as a formality.
Should I be worried about a CERT audit if selection is random?
You should respond to it with full rigor. Random selection does not protect you: if the documentation does not support the claim, the claim is denied and the payment is recovered. CERT findings also feed the national improper payment data that CMS uses to direct RAC and SMRC activity, so incomplete responses contribute to increased scrutiny of the entire service category.
When should I involve an attorney in an audit?
Immediately for any UPIC or OIG matter, any matter referencing investigation rather than payment review, and any matter involving extrapolation with significant dollar exposure. For routine MAC probes, TPE Round 1, and CERT requests, experienced audit defense consultants are often sufficient, though counsel should be consulted if findings suggest a pattern or if the matter escalates.
Can an audit lead to False Claims Act liability?
Yes. The FCA knowledge standard encompasses reckless disregard and deliberate ignorance, not merely actual knowledge. Audit findings that a practice failed to remediate can establish that the practice knew or should have known claims were improper. This is why unaddressed audit findings are substantially more dangerous than the findings themselves.
How far back can a Medicare audit go?
It depends on the contractor and the review posture. RACs reviewing under the baseline annual ADR limit may look back three years from the claim paid date, while those reviewing under an adjusted ADR limit work from a six-month look-back. UPIC and OIG matters involving suspected fraud can reach further, and False Claims Act limitations periods extend well beyond typical audit look-back windows.
How can DoctorsManagement help with a Medicare audit?
DoctorsManagement provides audit response management, extrapolation defense with statistical and economic expertise, appeal representation through all five levels, coding and documentation review, litigation and expert witness support, and post-audit remediation. Contact us at www.doctorsmanagement.com/contact-us or call (800) 635-4040.
External Resources and References
- CMS Medicare Overpayments Fact Sheet (MLN006379)
- CMS Medicare Financial Management Manual, Chapter 4: Debt Collection
- CMS Regulations and Guidance
- OIG Report: Medicare Contractors Were Not Consistent in How They Reviewed Extrapolated Overpayments
- OIG Work Plan
- OIG Fraud and Abuse Laws for Physicians
- OIG Self-Disclosure Information
- ACEP Recovery Audit Contractor (RAC) FAQ
- DoctorsManagement Audit Appeal and Defense
- DoctorsManagement Healthcare Compliance Audit
- DoctorsManagement Coding and Documentation Review
- DoctorsManagement Total Compliance Solution
This article is provided for informational and educational purposes only and does not constitute legal advice. Audit procedures, deadlines, and contractor authorities are subject to change, and the appropriate response to any specific audit depends on its particular facts. Practices facing an audit should consult qualified legal and compliance professionals. DoctorsManagement is available to provide audit defense consulting and can assist practices at any stage of the audit and appeal process.