Burnout, Boundaries, and Compliance
Leadership, Quality

Beyond Inspection Day

Building a Culture of Continuous Clinic Readiness 

Written by Misty Kelly, OHCC, HPOC with Corliss Collins, BSHIM, RHIT, CRCR, CCA; Nancie Lee Cummins, CFE, CHA, CIFHA, OHCC, CHCM, CHCO CORCM, CRAS; Joy Rose, MSA, RHIA, CCS, CHA, CHPS; and Lorianne Sainsbury-Wong, Esq. 

Checklists provide structure and consistency, but they should not become the inspection itself. The true value of an inspection lies in validation, observation, and determining whether a process is actually working as intended. “A clinic cannot inspect its way into quality/compliance. Quality/Compliance has to be built into daily operations. Audit readiness should be a daily practice, not event based.”

Inspection Readiness Is Not an Event

Many organizations begin preparing for an inspection only after learning that a regulator, accrediting body, payer, auditor, or other external reviewer is scheduled to visit. Policies are reviewed, binders are updated, logs are checked, and staff receive last-minute reminders. While preparation is important, true readiness cannot be built in the days or weeks leading up to an inspection.

A successful clinic inspection program is not measured solely by how well a site prepares for a scheduled visit. It is measured by how consistently compliant processes are maintained when no inspection is expected. Organizations that embed compliance into daily operations are better positioned to respond when outside reviewers arrive because readiness has become part of the culture rather than an event on the calendar.

Corliss Collins noted, “A clinic cannot inspect its way into quality/compliance. Quality/Compliance has to be built into daily operations. Audit readiness should be a daily practice, not event based.” - This statement reflects one of the most important lessons I have learned through years of conducting clinic inspections: an inspection can evaluate readiness, but it cannot create it. Readiness is created through the work that occurs every day between inspections.

Define What Readiness Means in Your Organization

Before developing or enhancing an inspection program, compliance professionals should clearly define its purpose and scope.

This may seem obvious, but organizations vary considerably in how compliance responsibilities are assigned. In some organizations, Compliance oversees a broad range of operational, regulatory, privacy, safety, and accreditation functions. In others, responsibilities such as infection control, medication management, employee safety, credentialing, and medical records may be owned by separate departments.

Lorianne Sainsbury-Wong emphasized the need to understand “what you own and what you don’t own.” She explained that an observation may overlap with more than one department, but the organization’s structure and assigned responsibilities should guide how that concern is evaluated, communicated, and followed through.

The inspection scope should answer several basic questions:

  • What requirements will the inspection evaluate?
  • Which areas are owned by Compliance?
  • Which findings require collaboration with another department?
  • Can the clinic readily produce the records, documentation, and evidence upon request?
  • Who is responsible for correcting each type of deficiency?
  • How will corrective actions be documented, escalated, and validated?
  • What evidence will demonstrate that the correction was sustained?

A clearly defined scope prevents gaps, reduces duplication, and helps ensure the right department is accountable for the right process. Just as important, clinics need to understand what readiness looks like before Compliance arrives. Nancie Cummins stated, “A process needs to be in place for individuals to be able to follow guidelines. Some individuals have a background in compliance, and it may be easier. I have found most need guidelines for structure to be able to come up with an effective plan.”

In my experience, inspection success rarely comes from surprise. It comes from providing clear expectations, practical tools, and sufficient opportunity for clinics to assess themselves before the inspection occurs. I often describe our program as an open-book test. The purpose is not to surprise the clinic; it is to determine whether expectations have been understood, implemented, and maintained.

A Clean Clinic Does Not Always Mean a Compliant Clinic

Visible readiness is important. Clean exam rooms, organized records, current postings, and completed logs all contribute to a safe and professional environment. However, appearances do not always tell the whole story.

Corliss Collins captured this distinction well, “A clinic may have clean exam rooms, completed logs, and organized binders, but still have weak processes.”

A clinic can appear inspection-ready while still having significant gaps beneath the surface. Staff may be completing a task without understanding its purpose. A log may be present but completed inconsistently. A policy may be accessible but not reflected in actual practice. A correction may have been made after the prior inspection but never incorporated into the daily workflow.

Corliss Collins also noted that many clinics are prepared to “look inspection-ready,” but not necessarily prepared to “prove process control.” She identified recurring concerns such as policy-to-practice gaps, training-to-competency gaps, repeat findings, document-control problems, weak recordkeeping, siloed departments, and limited leadership support.

That is why meaningful inspections need to evaluate more than what is visible on inspection day.

Move Beyond Documents and Evaluate Process Effectiveness

Document review is an important part of the inspection process. Policies, logs, licenses, certifications, training records, and required postings provide evidence that key compliance activities have occurred.

However, the existence of a document does not necessarily demonstrate that the underlying process is effective. Consider the difference:

Inspection Element

Question to Ask

Documentation

Does the required record exist?

Implementation

Is the process actually being followed?

Knowledge

Can employees explain their responsibilities?

Effectiveness

Is the process producing its intended result?

Sustainability

Is the process being maintained between inspections?

This distinction appears frequently in actual clinic inspections. For example, a clinic may perform its required monthly crash cart review, but replacement pull-tag numbers may not be consistently documented. In that situation, activity is occurring, but the documentation does not fully demonstrate control of the process.

Similarly, a clinic may complete routine safety checks but be unable to produce the related monitoring log. The missing document does not automatically mean the activity never happened, but it does mean the organization cannot verify that the process was performed consistently or reviewed appropriately.

The same issue arises when required employee records are incomplete. During recent inspections, clinics generally demonstrated strong operational knowledge, yet findings still occurred because required consents or declination forms were not available.

These are often correctable findings, but they also illustrate a broader compliance principle:
If an organization cannot demonstrate that a required activity occurred, the strength of the underlying practice becomes more difficult to defend.

Corliss Collins mentioned, “There is a big difference between a checklist and an audit. Always investigate, vet, verify, and validate everything based on evidence. Do not confuse activity with effectiveness.” 

Checklists provide structure and consistency, but they should not become the inspection itself. The true value of an inspection lies in validation, observation, and determining whether a process is actually working as intended.

Readiness Extends Beyond Formal Regulatory Surveys

When people hear the phrase “clinic inspection,” they often think first about a governmental, licensing, certification, or accreditation review. Actual clinic readiness is much broader. Payer visits, managed care audits, credentialing reviews, complaint investigations, privacy inquiries, and other external evaluations may all expose weaknesses in daily operations.

Lorianne Sainsbury-Wong emphasized that these visits should be approached with the same level of care given to formal regulatory or accreditation surveys. She also made an important observation, “What they see, what they hear, what they observe” matters from the moment a visitor enters the facility.

That observation extends beyond inspection preparation. It includes whether required postings are visible, whether conversations protect patient privacy, whether staff know how to respond to questions, whether restricted areas are appropriately secured, and whether daily operations reflect the organization’s written expectations.

External reviewers do not experience a clinic through its policies alone. They experience it through its people, environment, documentation, and processes.

  • A balanced inspection model may include:
  • Routine self-audits
  • Scheduled educational or readiness activities
  • Focused reviews of higher-risk processes
  • Periodic unannounced validation
  • Timely feedback and corrective-action support
  • Follow-up monitoring to confirm sustained improvement

The combination provides both preparation and a realistic assessment of day-to-day readiness.

When Findings Repeat, Look Deeper

An isolated mistake may require a straightforward correction. A recurring finding demands a different conversation. When the same type of finding continues to appear, the question should not be limited to:

  • Why did this employee make a mistake?
  • The organization should also ask
    • Why did this process fail again?

Joy Rose noted that many compliance challenges are not rooted in a lack of knowledge, but in a failure to consistently execute established processes. That resonated with me because it mirrors what we frequently encounter during clinic inspections. Most clinics understand the expectations. The greater challenge is maintaining those expectations consistently between inspections.

Repeat findings may indicate:

  • An unclear or impractical workflow
  • Inadequate training or competency validation
  • Insufficient resources
  • Competing operational priorities
  • Unclear accountability
  • A lack of leadership reinforcement
  • Poor document control
  • A corrective action that addressed the immediate finding but not its cause

Recent inspection trends within our organization demonstrate why this matters. Many clinics performed extremely well, with 17 achieving scores of 95% or higher and three achieving perfect scores. However, lower-scoring clinics frequently showed evidence that a meaningful self-audit had not been completed.

Many deficiencies could have been identified and corrected before the onsite review. Documentation remained the most common category of findings, and the issues generally reflected inconsistent execution rather than an absence of guidance or resources. These results reinforce two important points:

  • First, the standards are attainable.
  • Second, providing information does not guarantee that it will be consistently applied.

Corrective action should therefore extend beyond fixing the immediate item. It should determine why the requirement was missed, who owns the ongoing process, and what evidence will demonstrate that the correction has become part of normal operations. Corliss Collins advised that compliance professionals should “implement root cause thinking early.” 

Keep Inspections Educational, Not Punitive

Inspections should never feel like a “gotcha” exercise. Employees who perceive inspections as punitive may become defensive, provide limited responses, or avoid asking questions. None of those reactions improve compliance.

A supportive approach does not mean lowering standards or overlooking deficiencies. It means conducting the review professionally, explaining the reason behind the requirement, acknowledging areas of strong performance, and helping the clinic understand what must happen next. An educational inspection should include:

  • Clear expectations
  • Objective observations supported by evidence
  • Recognition of areas that are working well
  • Explanation of identified risks
  • Specific corrective-action requirements
  • Access to appropriate tools and resources
  • Follow-up to confirm completion and sustainability

The site should leave the inspection understanding what needs to improve, why it matters, and who is responsible for the next step. Our clinic administrator survey provides helpful support for this approach. Their feedback was overwhelmingly positive. Respondents consistently described the inspection process as professional, supportive, educational, and valuable in helping them better understand compliance expectations.

Survey results reinforce that accountability and partnership can coexist within the same inspection program. Those results matter because a rigorous inspection and a positive experience are not mutually exclusive. Compliance can hold clinics accountable while still treating the people involved with professionalism and respect.

There is value in both announced and unannounced inspection activities. Scheduled reviews give clinics time to gather records, coordinate with supporting departments, complete thoughtful self-audits, and address questions before the inspection. Unannounced or “pop-in” inspections more closely reflect the conditions a clinic may face if an outside agency arrives without advance notice.

Our program evolved from scheduled inspections to pop-in reviews after clinics had received preparation tools, checklists, guidance, and ongoing education. The purpose was not to create anxiety or catch employees off guard. It was to determine whether established expectations were maintained under normal operating conditions. At the same time, an inspection should account for the realities of the clinical environment. Staff members are managing patient care, urgent operational needs, and competing responsibilities.

Lorianne Sainsbury-Wong recommended: “Advance communication, planning, team collaboration efforts to maintain consistent messaging and reduce stress levels as many staff fear being put on the spot if questioned during an onsite inspection.”

The goal should be realistic validation without unnecessary intimidation. When arriving for a pop-in inspection, I remind staff that Compliance understands the process can feel stressful. We are not there to act as the police. We are there to help identify and correct vulnerabilities before an external regulator identifies them under far less forgiving circumstances.

Leadership and Operational Ownership Matter
The Compliance department may design the inspection process, perform the review, report deficiencies, and monitor corrective actions. It cannot single-handedly maintain readiness at every clinic. Readiness lives in daily operations.

Clinic and department leaders help determine whether self-audits are meaningful, whether required records are maintained, whether staff receive sufficient time and support, and whether corrective actions remain in place after the inspection closes. When expectations are repeatedly communicated but the same findings continue to appear, additional training may not be the only answer. The organization may need to examine whether leaders are reinforcing the requirements, reviewing completion, removing operational barriers, and holding the appropriate individuals accountable.

Lorianne Sainsbury-Wong emphasized the value of “Proactive communications, structured planning regulatory compliance oversight, and organizational alignment are essential components of effective inspection readiness. Leadership should focus on equipping team with clear guidance and consistent messaging so that inspections serve as an objective assessment of compliance, quality, and operational performance, not a disruptive event in daily work.”

That partnership is essential. Compliance provides oversight and an independent perspective. Operations own the daily processes. Supporting departments provide subject-matter expertise and maintain records within their areas. Leadership ensures identified risks receive the attention and resources necessary for sustainable correction. Continuous readiness depends on all of them.

Questions Every Compliance Professional Should Ask

Before concluding a clinic is inspection-ready, consider:

  • Are policies current, approved, and accessible?
  • Can staff explain the responsibilities?
  • Does documentation support actual practice?
  • Are self-audits identifying concerns before Compliance does?
  • Are corrective actions addressing root causes?
  • Would the clinic perform the same way tomorrow if an external inspector arrived unexpectedly?

The answers often reveal more about organizational readiness than any score or checklist alone.

Conclusion

Meaningful clinic inspections are not simply about finding deficiencies. They are about determining whether written expectations have become part of daily operations.

Organizations that embrace continuous readiness spend less time preparing for inspection day and more time maintaining effective processes. Employees understand their responsibilities, leaders reinforce expectations, and corrective actions become operational improvements rather than temporary fixes.

A strong inspection program provides structure, identifies risk, validates effectiveness, and creates opportunities for education. It also recognizes when a finding reflects more than an isolated mistake and requires a closer examination of leadership, workflow, resources, or accountability.

Ultimately, the best measure of readiness is not how a clinic performs while the inspector is standing in the building. It is how the clinic performs every day when no inspection is expected.

About the Author & Contributors

Misty Kelly, OHCC, HPOC, serves as Compliance & Privacy Officer for InnovaCare Health and has more than 23 years of experience in healthcare compliance, privacy, auditing, regulatory affairs, and risk management.

Misty serves as an AIHC Education Volunteer and project manager for this article. AIHC Education Volunteer contributors to help make this article happen are Corliss Collins, BSHIM, RHIT, CRCR, CCA; Nancie Lee Cummins, CFE, CHA, CIFHA, OHCC, CHCM, CHCO CORCM, CRAS; Joy Rose, MSA, RHIA, CCS, CHA, CHPS; and Lorianne Sainsbury-Wong, Esq.

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
Healthcare Revenue Cycle Compliance
Billing/RCM

Common Compliance Risks in OB/GYN Medical Billing and How to Address Them

Written by Noah Smith for BillingFreedom

The article will help healthcare professionals identify common compliance risks that can arise in OB-GYN medical billing and understand practical approaches for addressing those risks through accurate documentation, coding, claim review, internal audits, and consistent billing workflows.

OB/GYN billing can get complicated quickly. During the same week, a practice may bill for preventive visits, ultrasounds, office procedures, prenatal care, surgery, delivery services, postpartum visits, and treatment for unrelated gynecologic conditions. Those services do not always follow the same documentation, coding, or payer rules. That leaves plenty of room for small mistakes to slip into the billing process.

Sometimes the problem is obvious. A claim is rejected because the subscriber number is wrong or a required field is missing. Other problems are harder to notice. A payer may process a claim even though the documentation is weak, a modifier has been used inconsistently, or staff are following an outdated billing process.

One paid claim does not necessarily tell a practice that everything behind the claim was handled correctly. A better way to think about compliance is to look at the entire path a claim takes:

  • Patient information has to be accurate.
  • Coverage needs to be checked.
  • The provider's note has to support the service.
  • Coding needs to match the record, and payer requirements have to be addressed before the claim goes out.

When one part of that chain breaks down repeatedly, the problem can spread across dozens of claims before anyone recognizes the pattern.

Where OB/GYN Billing Problems Usually Start

Many compliance issues begin before a coder ever looks at the chart. Consider a returning patient whose insurance changed since her last appointment. If the old plan is still listed in the system, the claim may be sent to the wrong payer. By the time the rejection comes back, staff may need to update the account, verify benefits again, rebill the service, and make sure a filing deadline has not been missed.

Authorization problems can develop in much the same way. A service may have been appropriate and clearly documented, yet the claim can still run into trouble if the payer required prior authorization and nobody confirmed it.

Then there is the medical record itself. A provider may remember exactly what was discussed or performed during a visit, but the billing team can only rely on what appears in the documentation. If the note does not clearly support the service being reported, defending the claim later becomes much more difficult.

The Centers for Medicare & Medicaid Services (CMS) provides guidance on electronic healthcare claims and the information needed for claims processing. The larger point for a practice is simple: compliance starts long before a denial or payer review arrives.

Documentation and Coding Need to Tell the Same Story

Documentation and coding are often discussed as separate tasks. In actual billing, they are difficult to separate. The code on the claim is supposed to represent what happened during the encounter. The medical record is what supports that representation.

Problems begin when the two tell different stories.

A common OB/GYN situation is a preventive visit in which the patient also brings up a new medical concern. Additional evaluation may take place during the same encounter. Whether separate reporting is appropriate depends on the services performed, the documentation, coding rules, and the payer's requirements. Similar questions come up with procedures, diagnostic testing, postoperative care, maternity services, and modifier use.

A diagnosis code may be valid in general but still fail to match what the provider actually documented. A procedure code may describe a service correctly but lack enough support in the chart. A modifier can also create problems when staff use it routinely instead of deciding whether the circumstances of that particular encounter justify it. These are not always dramatic errors. That is part of the problem.

When the same documentation habit or coding shortcut is repeated week after week, an isolated weakness can turn into a larger compliance concern.

Periodic chart-to-claim reviews can help uncover those patterns. Instead of asking only whether the claim was paid, the reviewer looks at whether the claim accurately reflects the record and whether the documentation is strong enough to support what was billed.

Some Claim Errors Have Nothing to Do with Complex Coding

Not every denied or rejected claim involves a difficult coding question. Sometimes the problem is a wrong date, an outdated insurance record, missing provider information, an incorrect subscriber ID, or a claim field that was left incomplete. These errors may sound minor, but they still consume staff time and slow down payment.

Electronic claims generally pass through automated edits during processing. Certain missing or inconsistent details can cause the claim to stop before it gets very far.

A short review before submission can catch many of those problems. Staff may want to verify:

  1. Patient and subscriber information.
  2. Current insurance coverage and coordination of benefits.
  3. Provider and practice identifiers.
  4. Diagnosis codes, procedure codes, and modifiers.
  5. Documentation supporting the billed service.
  6. Required authorization or referral information.
  7. Payer-specific claim requirements and missing fields.

The review does not have to turn into a lengthy approval process for every claim. What matters is that the practice has a reliable way to catch repeatable errors before the payer does.

Eligibility Deserves More Attention in OB/GYN Billing

Insurance information can change during the course of care, and OB/GYN practices are especially likely to encounter that issue because many patients receive services over an extended period.

Pregnancy is an obvious example. A patient may have one insurance plan early in the pregnancy and another later. Employment can change. A spouse's coverage can change. Coordination of benefits may need to be updated. Authorization rules may also be different under the new plan. If staff rely on an eligibility check performed months earlier, the billing team may not find out about the change until a claim is denied.

Eligibility problems can affect more than reimbursement. They may also result in the wrong amount being assigned to the patient or create confusion about who is financially responsible for the service.

Checking coverage at appropriate points throughout treatment gives staff a chance to address those issues before the claim has already gone through the billing cycle. It also makes financial conversations with patients more accurate.

A Denial May Be Pointing to a Workflow Problem

Correcting a denied claim is necessary. Correcting the same type of denial twenty times should raise a different question - Why does it keep happening?

Suppose claims for a particular procedure regularly come back because information is missing. Billing staff can add the information and resubmit each claim, but that does not explain why the original claims were incomplete.

Maybe the registration team is not collecting something the payer requires. Perhaps the authorization information exists but is not being transferred correctly. It could also be that staff misunderstood a payer policy. The denial itself is only the visible part of the problem.

This is why useful denial management goes beyond counting how many claims were denied. Practices can look at which reasons occur most often, which payers are involved, whether one service keeps appearing, and where in the workflow the original error began.

That kind of review can reveal patterns that would otherwise remain hidden. The CMS Medical Review and Education resources also discuss claims analysis and medical record review in the context of identifying improper billing and documentation issues. For an OB/GYN practice, denial data can serve as a practical warning system. It shows where the revenue cycle is struggling, not just where payment was delayed.

Internal Audits Can Be Small and Still Be Useful

An internal audit does not have to involve hundreds of charts. A practice can learn a great deal from a carefully chosen sample.

Maybe one modifier has been causing questions. Perhaps a particular payer has denied an unusually high number of claims. There may be concerns about preventive visits, maternity billing, surgery, medical necessity documentation, or another service that carries more risk. Those claims can be reviewed against the medical record.

The reviewer may find that everything was handled appropriately. If not, the next step is to determine whether the problem was isolated or whether it reflects a larger habit. That distinction matters. One coding mistake made on a single claim may require a simple correction. Finding the same mistake across several providers or multiple dates of service suggests that the practice may need education, a workflow change, or closer monitoring. The audit should not end when the error is identified.

If a change is made, the practice needs some way to determine whether it worked. Reviewing another sample later can show whether the same problem is still appearing. Without follow-up, the practice has documented a problem but has not necessarily solved it.

Compliance Works Better When It Is Part of Routine Operations

A compliance process does not need to be complicated to be useful. In many practices, consistency matters more than creating a large set of policies that nobody uses. Staff should know how registration is handled, when eligibility is checked, how authorization information is recorded, how claims are reviewed, what happens when a denial arrives, and who is responsible for following up on recurring problems.

Those processes should not exist only in one employee's memory. Training matters for the same reason. Payer policies change. Coding guidance changes. Internal workflows change. New employees arrive, and experienced employees sometimes continue using a process that made sense under an older rule.

Regular education gives the practice a chance to catch those gaps.

Billing data can also help determine where training is needed. If eligibility denials suddenly increase, the first response should not necessarily be a general coding seminar. The practice may need to look at registration and verification instead. If several claims involving the same modifier are being questioned, a focused review of those encounters is probably more useful than retraining the entire staff on every coding topic. Compliance becomes easier to manage when the response matches the actual problem.

Documentation Reviews Should Include the Claim

A chart can look complete on its own while the corresponding claim still contains a problem.

The opposite is also possible. A claim may appear technically correct until someone compares it with the medical record.

Looking at both together usually provides a clearer picture. This is particularly important for services where the circumstances of the encounter affect billing. Preventive care, problem-oriented visits, procedures, maternity care, and postoperative services can all raise questions that cannot be answered by looking at a code alone.

The reviewer needs to understand what actually happened during the visit, what the provider documented, and how that information was translated into the claim.

Preparing for Billing Changes Before They Reach the Claims Department

One of the easiest ways for a billing problem to spread is for a rule to change while the practice keeps following the old process. Changes may affect coding, documentation, payer policies, reimbursement, or the way certain services are reported.

The first sign should not have to be a wave of denials.

When a significant change is announced, the practice can identify which services will be affected and who needs to know about it. Providers may need different documentation. Billing staff may need revised procedures. Software settings or claim edits may also need to be updated. Testing the new process early is usually easier than correcting a backlog later. This becomes especially important when changes affect maternity services because the care and billing may span several months.

The Bigger Compliance Question

A claim can be paid and still come from a weak process. That is why payment should not be the only measure of whether an OB/GYN billing operation is working well. A better question is whether the practice could explain and support the claim if someone reviewed it later.

  • Was the patient's coverage checked?
  • Does the chart support the service?
  • Does the code match what was documented?
  • Were payer requirements addressed?
  • If a similar problem appeared last month, was anything changed afterward?

Those questions bring compliance into the normal revenue-cycle process instead of treating it as something that matters only during an audit.

Most billing problems do not begin as major compliance failures. They usually start much smaller: an insurance detail that was not updated, documentation that was a little too vague, a modifier applied out of habit, or a denial that was corrected without asking why it happened.

The risk grows when the same issue becomes routine.

Finding those patterns early is what gives a practice the best chance to correct them before they affect more claims, more patients, or more revenue.

About the Author Noah Smith

This article is written by Noah Smith on behalf of BillingFreedom. Noah is a medical biller, SEO and Content Outreach Specialist.

Additional Resources

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
Healthcare Revenue Cycle Compliance
Billing/RCM

Mitigating Compliance Risks in Genetic Testing Billing and Medical Necessity Claims

Written by: Ricky Bell 

Having spent a decade advising clinical laboratories and health systems on revenue cycle management, I can tell you that molecular diagnostics remains one of the most volatile operational areas in healthcare. Federal spending on genetic testing under Medicare Part B now sits above $3.6 billion every year. That rapid financial growth brought aggressive oversight from the U.S. Department of Health and Human Services Office of Inspector General (HHS-OIG) and the Department of Justice.

In the complex arena of medical billing, molecular diagnostic testing sits right in the crosshairs of federal auditors. Regulators no longer rely on random sampling. Instead, they deploy advanced data analytics to flag billing anomalies instantly. For compliance officers and practice managers, ensuring every claim meets strict coverage standards isn't just a recommendation—it is a survival strategy that lab executives cannot afford to sleep on. Rules change overnight. When billing protocols lack internal controls, financial penalties and False Claims Act liability follow quickly behind.


Where Labs Usually Get Burned

When reviewing Federal enforcement actions, one may find specific aspects of operations that lead to regulatory setbacks, including clawbacks and fines. For example, OIG has on multiple occasions published fraud alerts with the primary goal of targeting genetic testing practices and has pointed out that claims that result in financial penalties most often stem from major failure of the system's processes rather than from honest error.

Common High-Risk Testing Behaviors:

  • High-Risk Testing Behaviors.
  • Billing unbundled molecular CPT codes.
  • Bill a panel without a chart proof.
  • No signature by the doctor on the order.

Use of non-compliant lead-generation practices that may violate healthcare marketing regulations. Incorrect use of unlisted codes that relate to the genome.

Examine billing of multi-gene panels for cancer. Legal consequences come immediately when multi-gene hereditary cancer or pharmacogenomic panels are billed without showing the medical necessity of each individual gene target. Paying entities do not generally accept that a broadly screening panel is a medical necessity simply because a patient has a family history of disease. In addition, laboratory-marketing relationship set-ups frequently breach the Eliminating Kickbacks in Recovery Act (EKRA) and the Anti-Kickback Statute. When labs pay for marketing services in proportion to volume or claim value, they open themselves up to the possibility of being investigated by the Department of Justice, a common compliance issue that many lab managers face.

Navigating Medical Necessity and Coverage Controls

Defining medical necessity in genetics testing is really about finding a middle ground between clinical utility and coverage criteria determined by payers. An example is when a physician thinks a 50-gene panel is the ideal choice for giving the right diagnosis. Still, if the local coverage policy (LCD) lists just five genes as the only ones that are covered and the patient's condition is consistent with only these genes, then the doctor will be referring to the patient for the other testing that the insurance is not covering.

Maintaining billing compliance, organizations must master the requirements set by the Molecular Diagnostic Services (MolDX) program and commercial utilization management policies. Commercial payers and state Medicaid programs frequently diverge on prior authorization rules, creating administrative friction for billing staff. Truth is, what works for Medicare might fail completely with a commercial plan.

Key Operational Checks for Coverage:

  • Review local coverage rules monthly.
  • Get prior approval before testing.
  • Document clinical rationale in charts.
  • Verify specific CPT code coverage.
  • Check doctor order signatures daily.

A pre-test verification procedure is a compulsory setup. If a lab gets referrals from community physicians outside, it will be wrong to assume that the requesting provider already wrote medical necessity notes in their EMR. The lab on its own has to verify that clinical records back up the selected test panel before carrying out the test and presenting the charge. Not checking the chart papers exposes the lab to risks during an after-payment review of billing practices. So, you don't ever want to end up having that as your big error.

How to Build an Audit Framework That Works

To prevent improper payments, progressive health systems are moving away from passive retro-audits. Implementing an active Genetic Testing Stewardship Program (GTSP) provides a proven operational blueprint. For example, Nemours Children’s Health successfully curtailed unnecessary genetic testing orders by placing certified genetic counselors directly into the ordering workflow and embedding hard-stops in their Electronic Health Record (EHR) systems.

A solid internal audit framework evaluates claims both before submission and after payment. Health systems must establish routine internal controls that evaluate coding accuracy, physician intent, and documentation completeness.

Essential Audit Program Controls:

  • Add decision support in EHR.
  • Audit high-risk codes monthly.
  • Use genetic counselors as gatekeepers.
  • Track payer denial codes weekly.
  • Check fair market value rates.

Concurrently, compliance teams should conduct random quarterly audits on claims utilizing unlisted CPT® codes (such as CPT® 81479). Unlisted codes attract automatic payer scrutiny. If your team uses unlisted codes to bypass prior authorization or LCD restrictions, auditors will flag those claims for recoupment. Training billing personnel to double-check local coverage policies ensures that claims align precisely with current billing guidelines.

Real Exposure Under Federal Statutes

The risks linked to statutory non-compliance are not just limited to denial of claims.  Compliance risks related to molecular diagnostic services can have far-reaching consequences, including the imposition of heavy statutory penalties under the False Claims Act, Stark Law, and EKRA. Pursuant to the False Claims Act, if one submits claims for tests that do not have a documented medical necessity, this may result in the payment of triple damages plus the imposition of compulsory civil money penalties per claim.

Labs need to figure out as well, how they relate their working relationships, if any, with ordering physicians, and clinical consultants. It is a federal crime under anti-kickback laws to distribute free point-of-care testing devices, offer lavish consulting arrangements, or to provide generous collection fees to ordering clinics. Basically speaking, financial arrangements between you and a referrer should only be as much as the Fair Market Value (FMV) of the service actually done. Besides, having clear and complete documentation of FMV determinations and legal opinions is another defense measure that every lab board should definitely work on.

About the Author

Ricky Bell (https://www.dastifysolutions.com/team/rickybell/) is Head of Operations at Dastify Solutions, where he oversees healthcare operations, revenue cycle management, and compliance initiatives for physician practices, clinical laboratories, and healthcare organizations across the United States. With extensive experience in medical billing, coding compliance, denial management, and revenue cycle optimization, he helps healthcare providers strengthen operational efficiency while maintaining regulatory compliance.

Resources

  1. U.S. Department of Health and Human Services Office of Inspector General (HHS-OIG): Fraud Alert: Genetic Testing Scam.
    https://oig.hhs.gov/fraud/consumer-alerts/fraud-alert-genetic-testing-scam/
  2. American Health Law Association (AHLA): Fraud and Abuse Issues in Diagnostic and Molecular Testing.
    https://www.healthlawyers.org
  3. Centers for Medicare & Medicaid Services (CMS): MolDX: Molecular Diagnostic Tests (LCD L35025).
    https://www.cms.gov/medicare-coverage-database/view/lcd.aspx?lcdid=35025
  4. Kaiser Family Foundation (KFF): Coverage of Breast Cancer Screening and Prevention Services.
    https://www.kff.org/womens-health-policy/coverage-of-breast-cancer-screening-and-prevention-services/
  5. National Center for Biotechnology Information (NCBI / PMC): The Genetic Testing Stewardship Program: A Bridge to Precision Diagnostics for the Non-genetics Medical Provider.
    https://pmc.ncbi.nlm.nih.gov/articles/PMC9124555/

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
Compliance in Healthcare
Corporate Compliance

The Imperative of Documentation Integrity

Addressing the Healthcare Data Crisis 

Written by Joanne Byron, LPN, BS, CCA, CIFHA, CHA, COCAS, CORCM, CHCO, HPOC, OHCC, CMDP, ICDCT-CM/PCS 

The information in this article primarily applies to providers when recording patient encounters in their office or other places of service. Content is for educational purposes only and is not intended as consulting or legal advice.

Introduction

Clinical documentation represents the foundational pillar of modern healthcare, ensuring patient safety, care continuity, accurate reimbursement, and the ethical use of medical data for research. However, the healthcare industry is currently grappling with a severe data crisis driven by the proliferation of historical documentation errors.

  • The transition from paper-based charts to Electronic Health Records (EHRs), while designed to streamline operations and reduce medical errors, has inadvertently introduced systemic vulnerabilities that compromise the integrity of clinical data.

The modern healthcare data crisis is not simply a matter of lost or misplaced files; it is a systemic degradation of data quality caused by the cumulative effect of historical documentation errors. At the center of this crisis is the phenomenon known as "chart lore" or "note bloat," where inaccuracies and redundancies are perpetuated across multiple patient encounters.

Several structural and behavioral factors drive this crisis:

  • Overuse of Copy/Paste and Cloning: The implementation of EHRs introduced time-saving functionalities such as the "copy-forward" or copy/paste features. Studies have revealed that over 50% of the text in inpatient and outpatient notes is duplicated. This practice often results in carrying over outdated, irrelevant, or entirely incorrect clinical information (e.g., documenting an allergy that was proven false years prior), creating information overload and increasing the risk of adverse events.
  • Template and Drop-Down Menu Errors: The reliance on pre-populated templates and drop-down menus can lead to "mouse-click errors," where a provider accidentally selects a normal finding for an abnormal condition. These errors obscure the true "patient story" and result in contradictory or missing clinical context.
  • Patient Matching and Interoperability Failures: Poor data entry and fragmented system integration contribute to patient misidentification. Industry surveys indicate that up to 20% of patients may not be correctly matched to their records, leading to scenarios where providers make treatment decisions based on another individual’s medical history.
  • Defensive and Billing-Driven Documentation: Because healthcare systems rely on Evaluation and Management (E/M) codes and reimbursement structures, clinicians are often pressured to document excessively to satisfy complex billing requirements, rather than focusing purely on clinical utility. This return-on-investment approach distorts the clinical record and leads to defensive medicine.
    • In light of Evaluation & Management guidelines allowing time or medical decision-making for many codes, providers must remember, when time is used, the complexity of the visit must be reflected to support longer visit times (higher reimbursed codes). Payers will question when high levels of service are billed but the note does not reflect the amount of work to support reimbursement.

Artificial Intelligence and the Physician/Provider Burden

Ironically, the tools intended to make documentation easier, EHR systems, have become a leading driver of clinician stress and burnout. The "cognitive load" of navigating drop-down menus and templating systems detracts from face-to-face patient time. And now with Artificial Intelligence (ambient scribes) being integrated into clinical documentation, the burden can become overwhelming due to time to ensure there are no errors in the record. AI is being built of historical information that is peppered with errors, inaccuracy, and omissions.

Despite promised efficiency gains, a large multi-center study found that AI ambient scribes saved a relatively modest 16 minutes of documentation time per eight hours of care. Because physicians are ultimately responsible for the accuracy of their medical records, they are forced to shift cognitive effort from typing to auditing—carefully reviewing AI-generated text to ensure no critical data has been omitted or misstated

Integrating artificial intelligence (AI) as ambient scribes in clinical settings reduces documentation time but yields distinct error profiles. Studies from the National Library of Medicine indicate that up to 70% of AI-generated notes contain at least one error, with an average of 2 to 3 errors per note. Omissions are the most common mistake, accounting for 71% to 83% of all errors.

Breakdown of AI Errors

Research shows that the types and frequencies of errors vary widely by system:

  • Omissions: Occurring in roughly 70-80% of recorded mistakes, this happens when AI leaves out critical details. Studies note that over 40% of these omissions carry moderate to significant clinical importance (e.g., omitting comorbidities or medication side effects).
  • Additions: Representing 4% to 11% of errors, this occurs when the AI fabricates or inserts information that was never discussed.
  • Hallucinations & Wrong Outputs: Fabricated or severely misidentified medical terminology.
  • Misplacements: Occurring in 6% to 25% of errors, where the AI correctly transcribes the info but places it in the wrong section of the chart.

Documentation Integrity & Accuracy Metrics

While traditional self-documentation by doctors can also be fragmented, ambient AI drafts often capture a much higher volume of the spoken interaction. However, this can sometimes lead to an inverse problem of information overload for the physician reviewing notes for accuracy.

Patient Safety and Clinical Continuity

The primary purpose of any clinical note is to support continuous, high-quality patient care. Outpatient practices frequently treat patients across extended timelines and involve diverse clinical staff. Therefore, documentation integrity is critical for several interconnected reasons:

  • Preventing Diagnostic and Medication Errors: When previous providers fail to update active problem lists, or when notes contain contradictory information, the risk of adverse events skyrockets.
    • Accurate documentation ensures that allergy lists, historical diagnoses, and ongoing treatment regimens are clear, preventing medication interactions and duplicative testing.
  • Facilitating Coordinated Care: In an era of team-based care and interoperability, patient notes are often referenced by external specialists, primary care physicians, and allied health professionals.
    • Complete, up-to-date clinical notes give care teams a holistic view of a patient’s health journey, allowing them to make informed, data-driven decisions.

Financial Sustainability and Revenue Cycle

Documentation dictates reimbursement and an organization’s ability to support compliant billing and reimbursement. In outpatient settings, practices rely on Evaluation and Management (E/M) coding guidelines established by the Centers for Medicare & Medicaid Services (CMS) and the American Medical Association (AMA).

  • Reducing Claim Denials: Payers use automated systems to verify that documented services match the billed codes. Incomplete or vague documentation leads to high rates of claim denials, requiring expensive and time-consuming rework for billing staff.
  • Combating the "Cloning" Risk: EHRs offer time-saving features like "copy-and-paste," "carry-forward," and auto-fill. While efficient, these features frequently lead to documentation cloning, where notes contain outdated or clinically irrelevant information.
    • Payers increasingly view cloned notes as a compliance risk, which can lead to delayed payments or allegations of upcoding, leading to allegations of violating the False Claims Act.

The Clinical and Legal Repercussions

The accumulation of these errors across vast databases has severe, real-world consequences for patient safety and institutional liability. Regulatory bodies, including the Department of Health and Human Services (HHS) Office of Inspector General (OIG), heavily scrutinize outpatient billing. Ensuring documentation integrity limits the financial and reputational damage of audits:

  • Demonstrating Medical Necessity: Every medical service must be justified by documented medical necessity. Documentation must clearly demonstrate why a course of action was taken and what alternatives were considered. Without this, practices are vulnerable to recoupment during post-payment audits.
  • Combating Fraud, Waste, and Abuse: Accurate charting protects both the provider and the organization. Attempting to add missing information or diagnoses to a chart after an audit has been initiated is a serious legal violation that carries civil and criminal penalties. Maintaining real-time, tamper-evident documentation is the best legal defense for providers.
  • Patient Harm and Medication Errors: Data integrity issues directly impact diagnostic accuracy and treatment planning. Studies indicate that a significant percentage of EHR-related events—sometimes cited as over one-third of cases—have life-threatening potential. When providers are forced to skim through bloated records, critical changes in a patient's condition or medication history are frequently missed.
  • Artificial Intelligence and Big Data Limitations: The current push toward integrating artificial intelligence (AI) and machine learning (ML) into healthcare relies entirely on the premise of data accuracy. However, because a high percentage of EHR records contain documentation errors, predictive models are frequently built on flawed or "missing" data indicators, which compromises their clinical reliability and introduces unconscious biases into algorithmic decision-making.
  • Malpractice Liability: Legal teams increasingly scrutinize EHR meta-data and documentation errors during litigation. Many EHR-related malpractice liabilities stem directly from documentation errors and omission, making inaccurate record-keeping a major risk management concern.

Strategies for Restoring Documentation Integrity

Addressing the healthcare data crisis requires a fundamental shift in how documentation is viewed, created, and audited. Organizations must move beyond billing-centric metrics and prioritize true Clinical Documentation Integrity (CDI). We simply need more documentation professionals, specifically in the outpatient setting where most care is rendered.

Implement Continuous CDI Programs - Healthcare facilities must establish dedicated CDI teams that routinely review and audit charts for clarity, completeness, and clinical accuracy. However, it is important that auditors and those training providers in CDI have structured training themselves first. Not all coding and billing auditors are qualified to conduct a documentation integrity audit. By educating all those involved on best practices and modern documentation guidelines, organizations can ensure that the patient's medical history accurately reflects their current clinical state.

Engage with organizations for online CDI training to improve the basic understanding of a compliant medical record. Registering qualified staff and/or providers with an organization which is a Licensing/Certification partner with CMS is recommended, such as the American Institute of Healthcare Compliance which offers online training with option to Certify as a Medical Documentation Professional.

EHR Usability and Design Overhaul - Software vendors and IT departments must collaborate to redesign EHR interfaces. This includes implementing strict limits on copy-paste functionalities, utilizing anomaly detection tools to flag duplicated or contradictory text, and enhancing interoperability to reduce patient matching errors.

Structured Data Capture - Shifting from unstructured narrative notes to standardized, structured data formats allow for better data reuse, less error-prone information exchange, and more effective clinical decision support systems.

Patient Engagement as a Verification Tool - Opening up EHRs to patients—allowing them to access their own health records and actively report discrepancies—has proven to be an effective strategy for identifying and resolving embedded "EHRrors" before they cause harm.

Conclusion

The historical degradation of healthcare data integrity poses a significant public health threat, turning patient records from life-saving tools into repositories of perpetuated errors.

To mitigate this crisis, the healthcare ecosystem must prioritize actionable, systemic reforms. By investing in enhanced EHR design, responsible implementation of integrating AI, rigorous auditing and compliance, and a culture of clinical clarity, the industry can restore trust in medical data and safeguard patient lives.

Outpatient practices can no longer treat clinical documentation as a mere administrative byproduct. Documentation integrity is the structural backbone of patient safety, financial compliance, and legal protection. By actively investing in CDI processes, ongoing provider education, and optimized EHR workflows, outpatient practices can safeguard patient outcomes, reduce audit vulnerabilities, and restore clinician satisfaction.

About the Author

Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS is an executive educator with the American Institute of Healthcare Compliance, a Licensing/Certification non-profit partner with CMS. She shares her experience of over 40 years as a nurse, consultant, auditor, and investigator in the healthcare field.

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
Compliance in Healthcare
Corporate Compliance

Navigating the Complexities of Medicare Cost Report Compliance

Navigating the Complexities of Medicare Cost Report Compliance

Written by the American Institute of Healthcare Compliance Education Department 

The American Institute of Healthcare Compliance (AIHC) is a non-profit training organization offering certification to become a Certified Cost Report Specialist (CCRSSM) and is a Licensing/Certification Partner with CMS.  The information below is not all inclusive, is not legal or consulting advice and is for educational purposes only.

Introduction

Filing Medicare Cost Reports (MCRs) is a highly complex, high-stakes process involving intricate, frequently changing CMS regulations, extensive data allocation, and strict documentation requirements.  Due to the complexity, errors are frequent, according to findings reported by the Office of Inspector General (OIG).

As a cornerstone of the Medicare program, the MCR serves as the annual mechanism for providers to report descriptive, financial, and statistical data to CMS. Pursuant to 42 CFR §413.20(b), Medicare-certified providers are mandated to submit this comprehensive financial record to determine the proper settlement of costs for services rendered to beneficiaries. Beyond ensuring that interim payments accurately reflect actual costs, the MCR is critical for establishing future reimbursement rates, including wage indices, disproportionate share hospital (DSH) adjustments, and graduate medical education (GME) payments. Failure to file, or inaccurate filing, carries significant financial risks, making an understanding of these reports crucial for regulatory compliance and financial stability.

While frequently viewed as a burdensome regulatory filing, the MCR constitutes one of the most comprehensive, standardized, and publicly available sources of institutional financial data in the United States. As Medicare moves toward greater fiscal accountability, the MCR allows providers to identify operational inefficiencies, manage financial performance, and ensure compliance in a complex reimbursement landscape.

Which Organizations File MCRs?

Medicare-certified institutional providers, typically Part A providers, must file annual Medicare cost reports (MCR) to determine reimbursement, usually within 5 months (or 150 days) after the end of their fiscal year. These reports, filed to a Medicare Administrative Contractor (MAC), are required for hospitals, skilled nursing facilities, home health agencies, hospices, FQHCs, RHCs, and ESRD providers.

Institutional Providers Required to File Medicare Cost Reports:

  • Hospitals: Including general, psychiatric, rehabilitation, long-term care, and children’s hospitals
  • Skilled Nursing Facilities (SNFs)
  • Home Health Agencies (HHAs)
  • Hospice Providers:
  • Federally Qualified Health Centers (FQHCs):
  • Rural Health Clinics (RHCs)
  • End-Stage Renal Disease (ESRD) Facilities
  • Organ Procurement Organizations (OPOs)
  • Community Mental Health Centers (CMHCs)

When are Cost Reports Due to be Filed?

Providers should use the Medicare Cost Report Electronic Filing (MCReF) system for submissions.  The cost report is due on or before the last day of the fifth month following the close of the provider's fiscal year and filed to the provider’s Medicare Administrative Contractor (MAC).

  • Example: For a fiscal year ending December 31, the report is due May 31.
  • Non-Month-End Closings: If the fiscal year does not end on the last day of the month, the report is due 150 days after the last day of the cost reporting period.

Failure to submit can result in the suspension of Medicare payments, increased audit risk, and loss of reimbursement.

Key 2026 Medicare Advantage (MA) Cost Reporting Requirements

CMS requires Medicare-certified acute care hospitals reimbursed under the IPPS (inpatient prospective payment system) to report median negotiated payment rates from Medicare Advantage (MA) plans by MS-DRG on their annual cost reports for cost reporting periods ending on or after January 1, 2026.

This mandate aims to collect market-based data to set future inpatient prospective payment system (IPPS) relative weights.  Data will be used to set future MS-DRG weights likely by Fiscal Year 2029.

This requirement adds significant complexity to an already error-ridden annual Cost Report process. Providers must ensure the accurate reporting of MA negotiated rates to avoid potential audit findings, as this data will influence future payment setting.

OIG Audits CMS Contractor Cost Report Compliance

Take a look at some recent Office of the Inspector General (OIG) audit reports to see how large the financial impacts of noncompliance can be for MACs, which falls back onto the provider.

A September 2025 audit by the U.S. Department of Health and Human Services Office of Inspector General (HHS-OIG) found that Novitas Solutions, Inc. (Novitas), a Medicare Administrative Contractor (MAC), failed to properly review 100% of the cost reports examined in a specific sample.

  • The errors caused by inadequate reviews led to a total of $9.4 million in corrected final settlements, consisting of $5 million in overpayments and $4.4 million in underpayments to providers.

A similar, separate OIG audit released in September 2025 also found that National Government Services, Inc. (NGS) had a 100% error rate (64 out of 64) in a sample of reopened cost reports, resulting in $5.6 million in corrected settlements.

  • The 64 cost report reopening's resulted in corrected final settlements to providers totaling $5.6 million (which consisted of $3.1 million in overpayments and $2.5 million in underpayments).

Key Findings on Cost Report Errors:

  • High Error Incidence: A 2025 OIG report revealed that 12 Medicare Administrative Contractors (MACs) failed to meet oversight requirements, with a 70% failure rate in reviewing filings.
  • Specific Errors: Common errors included misclassification of physician salaries, improper nursing/allied health program calculations, and improper bad debt reporting.
  • Financial Impact: These errors resulted in massive financial inaccuracies, including one case involving over $250,000 in improper overpayments.
  • Audit Surge Expected: Due to these findings, an increase in audits and oversight by MACs is expected.

Common Causes of Errors:

  • Inconsistent Data Sources: Failure to reconcile internal financial systems with patient data (e.g., midnight census, revenue usage files).
  • Complex Allocations: Miscalculating the allocation of costs between Medicare and non-Medicare patients.
  • Failure to Update: Carrying over errors from previous years instead of updating with current data.

Implications of Errors:

  • Overpayment Recovery: MACs can claw back funds, requiring repayment with interest.
  • Underpayments: Errors can lead to lower-than-earned reimbursements.
  • Increased Audit Risk: High error rates trigger more intensive reviews and potential civil monetary penalties.

Notable Cases of Noncompliant Medicare Cost Reporting

  • Non-Compliance with Medicare Cost Reporting Requirements

In 2018 the Office of Inspector General (OIG) reported that the National Institute of Transplantation (NIT), an independent histocompatibility lab, did not fully comply with Medicare’s cost-reporting requirements.  In the cost report in question, NIT had correctly reported only 177 of 186 cost transactions.  In total, the OIG estimated that NIT had received approximately $45,940 in overpayments from Medicare. 

OIG concluded their audit report by recommending that NIT work with the Medicare Administrative Contractor to return potential overpayments and identify any additional similar overpayments that may be related to cost reports.

  • Referring Medicare Cost Reports and Reconciling Outlier Payments

Several years ago, two organizations were cited by OIG as not always correctly referring their Medicare cost reports to CMS.  For example, Cahaba Government Benefit Administrators, LLC (Cahaba GBA) had only referred 5 out of 13 cost reports with outlier payments that were qualified for reconciliation to CMS.  The financial impact of this noncompliance was estimated to be over $9,700,000 in total, of which just over $601,000 was due to Medicare. 

Another organization, CGS Administrators, a healthcare administrator operating as a Part A, Part B, and Home Health & Hospice (HH&H) MAC for Jurisdiction 15, had referred 15 of 18 qualified cost reports to CMS for reconciliation, but of those 15 referred reports, they had neglected to reconcile the outlier payments for 14 reports.  The financial impact of these affected reports was estimated at about $39,000,000 combined, with over $16,000,000 due to Medicare.

  • Non-Compliance with Medicare Organ Statistic Requirements

In 2012, LifeCenter Northwest, a federally designated independent organ procurement organization, was reported to have not fully complied with Medicare requirements for reporting organ statistics.  In the affected cost report, LifeCenter had reported incorrect organ statistics for 15 different organs. 

If was found that Medicare’s share of organ procurement costs was overstated by about $88,000.  OIG recommended that LifeCenter submit a revised cost report to correct the overstatement and work to ensure that future reports followed Medicare requirements.

Implement Strategies Now for Compliance

  1. Internal Routine Auditing: Implement proactive monitoring to verify that data—especially payroll and equipment costs—is accurate before submission.
  2. Incorporate Prior Audit Results: Avoid repeating adjustments from previous years, as recurring errors act as "red flags" for fiscal intermediaries.
  3. Rigorous Documentation: Maintain granular support for "allowable" costs, such as marketing (informational vs. promotional) and bad debt collection efforts.

Start by addressing critical high-risk components of the report.  CMS Auditors and the Office of Inspector General (OIG) focus on several key items within the cost report.  Your organization should also focus on these same areas when conducting internal compliance audits:

  • Graduate Medical Education (GME) & Indirect Medical Education (IME):
    • Inaccurate reporting of Graduate Medical Education (GME) payments, indirect medical education (IME) costs, and Medicare bad debts.  These involve complex resident counts and are frequent targets for in-depth audits.
  • Medicare Bad Debts:
    • Facilities must prove they used "reasonable" collection efforts for non-collectible deductibles and coinsurance. Improperly documented Medicare bad debts are a frequent source of audit findings.
  • Disproportionate Share Hospital (DSH) Payments:
    • Disproportionate Share Hospital (DSH) calculations are considered high-risk audit areas on the Medicare Cost Report. Due to the complexity of the regulations and the significant financial impact on reimbursements, these calculations frequently lead to errors, underpayments, or overpayments, according to the OIG.
  • Schedule S-10 (uncompensated care UCC):
    • Worksheet S-10 is a major audit trigger as it directly affects reimbursement rates.  Auditors target improper documentation of uncompensated care on Schedule S-10, which impacts UCC/DSH payments.  As of 2026, Medicare Administrative Contractors (MACs) are scrutinizing these filings, focusing heavily on documentation that supports charity care and bad debt, according to CMS.
    • The UCC and DSH go hand-in-hand as an add-on to the DRG reimbursement, but are calculated separately. 
  • Wage Index Data:
    • This data is used to set future prospective payment rates; inaccuracies can lead to billions in misapplied funds.
  • Operational Deficiencies:
    • Late submissions, inadequate training of staff, and poor oversight of third-party contractors can lead to compliance issues.
  • Vaccinations: 
    • Vaccinations are considered a high-risk error area on Medicare cost reports for Rural Health Clinics (RHCs) and Federally Qualified Health Centers (FQHCs). Errors often arise from failing to reconcile interim payments with actual costs, lacking proper documentation (logs, invoices, time studies), and missing or incorrect coding (e.g., Condition Code A6) on claims.

Conclusion - Include Cost Report Audits in Your Compliance Program

Because Compliance Officers often overlook the high-risk area of cost reporting, it is important to implement internal routine auditing and monitoring to ensure data submitted is accurate and timely.

Your Compliance Department should be overseeing areas which can pose a high financial or legal risk to the organization.  Cost reporting falls into both categories, requiring internal auditing and monitoring of this function to ensure accuracy and timeliness is observed.

Inaccurate filing or late submissions can result in immediate payment suspension, civil monetary penalties, or exclusion from the Medicare program.  All this can be avoided through appropriate preparation and accurate training.

This article is written by the American Institute of Healthcare Compliance Audit Education Department

References

American Institute of Healthcare Compliance (AIHC®)

CMS

Code of Federal Regulations

Noridian Healthcare Solutions

Office of Inspector General

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
Compliance in Healthcare
Corporate Compliance, Quality

From National Patient Safety Goals to National Performance Goals

Executive Accountability, Accreditation Readiness, and Outcome-Based Compliance in 2026 Written by Stacey Atkins, PhD, MSW, LSW, CPC, CIGE 

As healthcare organizations enter 2026, regulatory oversight continues to shift away from task-based compliance toward measurable outcomes, leadership accountability, and system-level performance. A defining example of this evolution is the Joint Commission’s replacement of National Patient Safety Goals (NPSGs) with National Performance Goals (NPGs), effective January 1, 2026.

This article is for educational purposes only to provide an executive and auditor-facing analysis of the NPG framework, examining regulatory intent, accreditation implications, and alignment with the Centers for Medicare & Medicaid Services (CMS) Conditions of Participation (CoPs). Practical guidance is offered to support governing boards, executive leadership, and compliance professionals in integrating NPG expectations into enterprise compliance, quality, and risk management programs.

Introduction

Healthcare compliance oversight in 2026 reflects a decisive regulatory transformation. Accrediting bodies and federal regulators are increasingly emphasizing outcome accountability, leadership engagement, and sustained performance improvement rather than episodic documentation compliance. Within this context, the Joint Commission’s transition from National Patient Safety Goals (NPSGs) to National Performance Goals (NPGs) represents a structural and philosophical shift with significant implications for hospitals and critical access hospitals.

As highlighted by the American Institute of Healthcare Compliance (AIHC), the NPG framework consolidates elevated Joint Commission requirements into a unified, outcomes-focused chapter aligned with CMS Conditions of Participation. While the underlying requirements largely pre-existed, the NPG structure reframes how organizations are evaluated, increasing scrutiny of governance, leadership oversight, and data-informed decision-making.

Regulatory Evolution: From Prescriptive Safety Tasks to Performance Outcomes

National Patient Safety Goals historically served as targeted mechanisms to address discrete safety risks, such as medication errors, healthcare-associated infections, and communication failures. Over time, however, organizations frequently approached NPSGs as checklist items tied to survey cycles rather than as drivers of continuous improvement.

The National Performance Goal framework addresses this limitation by organizing fourteen measurable performance domains that emphasize outcomes rather than task completion. This evolution aligns with value-based care models and reinforces expectations that organizations demonstrate sustained, system-level performance rather than episodic compliance.

Alignment with CMS Conditions of Participation

A defining feature of the NPG framework is its intentional alignment with Centers for Medicare & Medicaid Services (CMS) Conditions of Participation (CoPs). CMS CoPs establish baseline federal requirements for participation in Medicare and Medicaid programs. The Joint Commission’s NPGs clarify expectations that exceed these minimum standards, thereby signaling areas of heightened regulatory and accreditation focus.

For compliance leaders, this alignment underscores the necessity of integrating accreditation readiness with CMS survey preparedness.

  • Performance deficiencies identified through NPG evaluation may expose organizations to downstream risk during CMS audits, enforcement actions, or corrective action reviews.

Elevated Focus Areas and Sustained Regulatory Oversight

Although the NPG framework emphasizes flexibility in achieving outcomes, certain high-risk domains retain explicit regulatory requirements. Goals addressing suicide risk reduction and care planning and evaluation continue to require prescriptive safeguards due to their association with patient harm and regulatory enforcement history.

This dual structure reinforces that outcome-based compliance does not eliminate the need for evidence-based controls in high-risk areas. Executive leadership must ensure these domains receive sustained oversight, resource allocation, and performance monitoring.

Executive and Board Accountability Under the NPG Framework

The transition to National Performance Goals elevates accountability beyond frontline operations to executive leadership and governing bodies. Surveyors increasingly assess how boards and senior leaders oversee quality metrics, respond to performance trends, and allocate resources to address identified gaps.

Organizations unable to demonstrate leadership engagement in performance oversight may face accreditation findings related to leadership standards, regardless of whether direct patient harm has occurred.

Compliance Risks of Superficial Implementation

A significant compliance risk during the NPG transition is treating the framework as a rebranding exercise. Organizations that update policies without strengthening data analytics, governance structures, and continuous monitoring mechanisms may fail to meet survey expectations. Effective NPG implementation requires interdisciplinary collaboration, integration with enterprise risk management, and routine evaluation of performance outcomes.

Survey Readiness in an Outcome-Driven Accreditation Environment

Survey readiness under the NPG framework requires a departure from document-centric preparation models. Surveyors are expected to evaluate how organizations use performance data to identify trends, implement corrective actions, and sustain improvements.

Best practices include outcome-focused mock surveys, alignment of dashboards with NPG domains, and leadership preparedness to articulate how performance data informs strategic decisions.

Conclusion

The replacement of National Patient Safety Goals with National Performance Goals represents a pivotal shift in accreditation and compliance oversight. By prioritizing outcomes, leadership accountability, and alignment with CMS Conditions of Participation, the Joint Commission has elevated expectations for organizational performance.

Healthcare organizations that proactively integrate NPG expectations into governance, compliance, and quality frameworks will be best positioned to mitigate regulatory risk and demonstrate sustained accountability in 2026 and beyond. 

About the Author - Dr. Stacey R. Atkins, PhD, MSW, LMSW, CPC, CIGE

Dr. Atkins is a Compliance Specialist working as a team member in the Education Department of the American Institute of Healthcare Compliance. Her career spans leadership roles with the Office of the State Inspector General, Department of Behavioral Health and Developmental Services, and HRSA, among others.

References

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
Auditing, Managing Denials Is Important to Good A/R Hygiene
Auditing, Corporate Compliance

Auditing for Anti-Kickback Statute Violations

Written by the AIHC Education Department 

About the AKS 

The Anti-Kickback Statute [42 U.S.C. § 1320a-7b(b)] 

The AKS is a criminal law that prohibits the knowing and willful payment of "remuneration" to induce or reward patient referrals or the generation of business involving any item or service payable by the Federal health care programs (e.g., drugs, supplies, or health care services for Medicare or Medicaid patients). Remuneration includes anything of value and can take many forms besides cash, such as free rent, expensive hotel stays and meals, and excessive compensation for medical directorships or consultancies.

In some industries, it is acceptable to reward those who refer business to you or your organization. However, in the Federal health care programs, paying for referrals is a crime.  

The statute covers the payers of kickbacks, those who offer or pay remuneration, as well as the recipients of kickbacks. Yes, the law applies to those who solicit or receive remuneration. Each party's intent is a key element of their liability under the AKS.

The Department of Justice (DOJ), the Department of Health and Human Services Office of Inspector General (OIG), and the Centers for Medicaid and Medicare Services (CMS) are all charged with enforcing these laws. Filing claims to any Federal healthcare program related to an AKS violation may also violate the False Claims Act (FCA). From there, it just gets more complicated because kickbacks in health care can lead to:

  • Overutilization
  • Increased program costs
  • Corruption of medical decision making
  • Patient steering
  • Unfair competition

The kickback prohibition applies to all sources of referrals, even patients. For example, where the Medicare and Medicaid programs require patients to pay copays for services, you are generally required to collect that money from your patients. Routinely waiving these copays could implicate the AKS and you may not advertise that you will forgive copayments. It can be used to induce patients to choose a specific provider's services or to prescribe their products instead of cheaper alternatives. However, you are free to waive a copayment if you make an individual determination that the patient cannot afford to pay or if your reasonable collection efforts fail. It is also legal to provide free or discounted services to uninsured people.

The Government does not need to prove patient harm or financial loss to the programs to show that a physician violated the AKS. A physician can be guilty of violating the AKS even if the physician actually rendered the service and the service was medically necessary. Taking money or gifts from a drug or device company or a durable medical equipment (DME) supplier is not justified by the argument that you would have prescribed that drug or ordered that wheelchair even without a kickback.

Consequences for Violating the AKS

AKS Criminal penalties and administrative sanctions for violating the AKS include fines, jail terms, and exclusion from participation in the Federal health care programs as follows:

  • Civil penalties: The CMPL allows the Office of Inspector General (OIG) to impose civil penalties for violations of the Anti-Kickback Statute. These penalties include a fine of up to $50,000 per violation plus three times the value of the illegal kickback (treble damages).
  • Criminal penalties: Violating the Anti-Kickback Statute is a felony and can also lead to criminal penalties, including fines of up to $100,000 and imprisonment for up to 10 years.
  • Other consequences: In addition to financial and criminal penalties, individuals found guilty of kickback violations can be excluded from participation in federal health care programs. The Office of Inspector General (OIG) has the authority to exclude both individuals and entities. Claims that include items or services resulting from a violation are not payable and may constitute false or fraudulent claims under the False Claims Act.

Criminals Target Healthcare Providers

Physicians make an attractive target for kickback schemes because you can be a source of referrals for fellow physicians or other health care providers and suppliers. As a provider, you decide what drugs your patients use, which specialists they see, and what health care services and supplies they receive. And criminals count on providers not understanding the law. This point stresses the need to audit for potential AKS violations and to have a healthcare attorney familiar with the AKS to review any agreements in advance to avoid an unlawful situation.

There are still handshake deals made, where there is no written agreement, where remuneration is made in exchange for some form of kickback. Even these “unwritten” arrangements should be audited for potential issues.

Auditors are typically not attorneys, but an internal auditor can receive training to review for potential violations, then refer questionable situations to the Compliance Officer who will forward to outside legal counsel for further investigation and corrective action.  Why outside legal counsel? In-house legal counsel is likely to have reviewed or written the agreement in question, creating a conflict of interest in being involved in any aspect of the audit process.

Common targeting methods

  • Payments disguised as legitimate compensation:
    • Paying providers for patient referrals disguised as "bonuses" or "referral fees".
    • Offering or paying for patient information that is used to market to potential enrollees.
    • Paying providers for "consulting," "advising," or "research" when the primary purpose is to secure referrals.
    • Overpaying doctors for speaking engagements.
    • Payments for office space, phlebotomy, or other services that are inflated or not legitimate, intended to be a form of compensation for referrals.
  • In-kind or indirect benefits:
    • Providing free or below-market rent, equipment, supplies, or staff.
    • Offering gifts or tokens of appreciation that could be perceived as a reward for referrals.
    • Giving practice subsidies or covering expenses that are not otherwise required.
    • Free or discounted office space or supplies.
    • Gifts, meals, or tickets to events.
  • Compensation based on referral volume or status:
    • Offering payments or bonuses that are based on the number of patients a provider refers to a particular plan or service.
    • Providing remuneration that is contingent on the health status or demographics of the patients referred.
  • Exploiting "safe harbors":
    • Structuring arrangements that appear to be compliant (e.g., professional courtesy programs or recruitment benefits) but have the primary purpose of inducing referrals.

Safe Harbor Considerations

Safe harbors are specific, pre-approved exceptions to the AKS that provide immunity from prosecution if followed precisely. They are voluntary, and not all financial arrangements have a safe harbor. An arrangement must meet all conditions of a specific safe harbor to be protected; partial compliance is not enough.

To be protected by a safe harbor, an arrangement must fit squarely in the safe harbor and satisfy all of its requirements. Some safe harbors address personal services and rental agreements, investments in ambulatory surgical centers, and payments to bona fide employees.

Congress set forth a number of factors to consider when developing safe harbors; while not binding with respect to any assessment of an arrangement that implicates the Federal anti-kickback statute (other than in the establishment or modification of safe harbors (see section 1128D(a)(2) of the Act, 42 U.S.C. 1320a–7d(a)(2)), they are instructive for assessing risk under the Federal anti-kickback statute.

For example, OIG’s advisory opinions frequently consider factors such as overutilization, increased costs to Federal health care programs, corruption of medical decision making, patient steering, and unfair competition.

One of OIG’s Compliance Program Guidance documents reiterates these factors by highlighting the following questions to help guide an assessment of any problematic arrangements or practices identified as a red flag:

  • Does the arrangement or practice have the potential to interfere with, or skew, clinical decision making?
  • Does the arrangement or practice have the potential to increase costs to Federal health care programs or beneficiaries?
  • Does the arrangement or practice have the potential to increase the risk of overutilization or inappropriate utilization?
  • Does the arrangement or practice raise patient safety or quality of care concerns?
  • Does the arrangement or practice raise concerns related to steering patients or providers to a particular item or service?

The health care community and its partners must be mindful of these types of factors and question arrangements that implicate the Federal anti-kickback statute. An affirmative answer to one or more of these questions is a red flag signaling an arrangement or practice may be particularly susceptible to the harm caused by fraud and abuse.

AKS Audit Checklist

To audit for Anti-Kickback Statute (AKS) violations, create a comprehensive inventory of financial relationships, assess existing contracts against AKS safe harbors, conduct internal reviews of transactions and billing, and implement a robust compliance program that includes regular monitoring and staff training. Key steps include analyzing payments to ensure they are for fair market value, are not tied to referrals, and that arrangements are documented properly with signed agreements and legal review.

  • Build an inventory of all financial relationships 
    • List all transactions -
      • Document all financial relationships and transactions with potential AKS implications, including those with physicians, vendors, and other healthcare entities.
    • Categorize relationships –
      • Group arrangements by type, such as physician recruitment, medical directorships, lease agreements, and professional service agreements.
    • Work with legal counsel –
      • Involve legal counsel to ensure no relevant relationships with government health care programs are missed.
  • Review and assess existing arrangements 
    • Check against safe harbors –
      • Compare each financial arrangement against the requirements of relevant AKS safe harbors. For example, safe harbor requirements often include a written agreement, specifies the services, is for at least one year, and compensation is at fair market value and not tied to the volume or value of referrals.
    • Verify compensation –
      • Ensure compensation is set in advance and is not changed retroactively, especially within the first year of a new contract. Compensation should not be based on referrals or revenue generated from referrals.
    • Examine billing practices –
      • Review billing and payment practices to confirm they align with contractual terms and are at fair market value.
  • Conduct data analysis and transaction-level audits 
    • Obtain relevant data –
      • Gather data from general ledgers, vendor files, payroll, and payment records.
    • Select a sample –
      • Randomly select a sample of payments for a detailed audit.
    • Validate transactions –
      • Cross-reference payments against supporting documentation, such as invoices, timesheets, and contracts.
    • Use data analytics –
      • Employ data analytics to identify patterns and trends that might indicate improper conduct. This is an area where implementing Artificial Intelligence programs can provide speed and accuracy.
  • Audit Results Can Strengthen the Compliance Program 
    • Implement policies –
      • Audit results can help the Compliance Department establish written policies and procedures for compliance with the AKS.
    • Provide training –
      • Regularly train staff and key stakeholders on the AKS and how to identify and report potential violations. This includes discussion with all providers during on-boarding and at least annually as part of compliance training.
    • Ensure due diligence –
      • Conduct due diligence on new and existing business partners and perform background checks, such as checking the OIG's exclusion list.
    • Monitor and report –
      • Create a system for ongoing monitoring and auditing and establish a confidential way for employees to report suspected violations.

Conclusion

Audits proactively uncover compliance gaps and vulnerabilities before they become a problem, allowing for corrective action to be taken.

Auditing for AKS (Anti-Kickback Statute) compliance is crucial for mitigating risk because it identifies and addresses vulnerabilities that could lead to severe legal penalties, financial fines, and reputational damage. Regular audits help ensure adherence to laws and regulations, protect company assets, and maintain the trust of stakeholders by demonstrating a commitment to ethical practices.

Monitoring for AKS violations helps to prove a commitment to ethical and legal conduct. These types of audits help maintain a positive brand image and public trust.

Remember, regular auditing fosters a company-wide culture of accountability and continuous improvement, where employees are more aware of and committed to compliance requirements.

About the AIHC Education Department

The American Institute of Healthcare Compliance (AIHC) Education Department provides classroom and web-based training and certification for healthcare administrators and professionals. It includes an enrollment department that processes registrations, and a research and development arm focused on creating new educational products. Learn more about short course and certification offerings in addition to free and low-priced Continuing Education Unit (CEU) certification renewal single short courses or CEU packages. Visit our website https://dev-main.aihc-assn.org/

References

  • Centers for Medicare and Medicaid Services - WPS Government Services on Waivers of Deductibles and Co-Insurance
  • Department of Justice Enforcement Activities
  • Office of Inspector General Fraud & Abuse Laws, Physician Roadmap
  • American Institute of Healthcare Compliance, Healthcare Compliance certification program

Copyright © 2025 American Institute of Healthcare Compliance All Rights Reserved

Read More
Auditing, Managing Denials Is Important to Good A/R Hygiene
Auditing, Corporate Compliance

Importance of Compliance Audits

What Compliance Officers & Lead Auditors Should Know

Written by the AIHC Education Department 

Introduction

Audits Must be Independent, Transparent and Objective - No one enjoys having their department reviewed; however, audits are a necessary and important part of your organization’s compliance program. When a review or audit is conducted, you want to know that the auditors are objective with no hidden agendas. We want to be confident that the audit is being conducted fairly and objectively. Which leads us to the next important topic - who does the Auditor and Compliance Officer report to?

How to Establish Fairness

Bias, whether conscious or unconscious, can lead to improper influence, inaccurate evaluations, and legal repercussions, so auditors must have the ability to recuse themselves to ensure objective decision-making and to maintain the organization’s trust.

The reporting structure is critical to maintain fairness and impartiality. The Lead Auditor, as well as the Compliance Officer, must be outside the line of management to ensure independence and avoid conflicts of interest. This separation allows them to effectively monitor operations, identify risks, and hold the organization accountable without fear of reprisal, which is essential for maintaining an effective compliance program and protecting the organization from legal and financial penalties.

A few important key reasons for separation from management are:

Independence and unbiased assessment - Being outside the direct management structure ensures an objective and unbiased evaluation of the organization's operations, free from internal pressures. Lead auditors and Certified Healthcare Auditors know that the best compliment received is that the audit was fair. 

This means auditors must avoid participating in a review where bias can be construed.

  • Auditors must avoid taking a position that isn't objective due to personal convictions, which can impact everything from audit scope to reporting.
  • Auditors never create the audit criteria.
    • Evaluate compliance based on objective factors and documented data, such as implemented policies and procedures as your audit criteria.

Avoidance of conflicts of interest – Your organization is wise to follow advice from the Office of the Inspector General (OIG) general compliance guidance which emphasizes that the Compliance Officer should not lead or report to the legal or financial departments to prevent conflicts of interest. For example, the legal department's role is to defend the organization, which can conflict with the Compliance Officer's role of identifying and reporting risks. This is important because the audit team generally reports to the Compliance Officer or Compliance Department.

Direct reporting structure is necessary: A direct reporting relationship to the CEO or board of directors allows compliance and audit officers to bypass management interference when necessary. This ensures complete transparency and empowers them to raise concerns between all levels of management and act on findings without fear of reprisal.

Enabling effective "checks and balances" - Separation from the reporting structure creates a system of checks and balances, a vision promoted by the OIG, which is crucial for achieving the goals of a compliance program and identifying issues before they become costly problems.

Audit Results Must be Reproducible - Audit results must be reproducible to ensure objectivity, reliability, and transparency. Reproducibility allows independent verification of findings, catching mistakes and biases, and building trust in the results. It is crucial for validating the audit process, supporting long-term research, and meeting professional standards.

Maintaining professional obligations - Keeping the compliance function separate from operational departments upholds the professional obligations of the role, which include risk identification and mitigation, which must be separate from those who may be responsible for operational outcomes.

Exceed OIG Audit & Compliance Objectives

OIG is the acronym for Office of Inspector General (OIG), which is a division within a government agency responsible for oversight, audits, and investigations to prevent waste, fraud, and abuse. These offices conduct independent reviews of an agency's programs and operations to ensure efficiency, effectiveness, and financial health, and they often operate with a degree of independence to better serve their oversight function.

Compliance Officers should have structured training in auditing and monitoring not only to understand and support the Lead Auditor, but also to perform their own essential functions effectively, proactively manage risks, and foster an organization-wide culture of compliance and accountability. Acquiring expertise in auditing and monitoring enhances a compliance officer's professional value and opens up career advancement opportunities within the organization or as an independent consultant.

  • Training equips compliance officers with the skills to identify, assess, and mitigate potential compliance risks and vulnerabilities before they escalate into serious issues or legal violations. This proactive approach helps the organization avoid costly penalties and legal repercussions.

The Compliance Officer also is required to understand the principles of auditing and monitoring to ensure reviews have been conducted according to appropriate, acceptable standards and in compliance with applicable rules and regulations. Specialized training transforms a compliance officer from a simple "rule-checker" into a strategic asset who actively contributes to the organization's resilience and long-term success. Obtaining certification in both compliance and auditing is recommended (choose a non-profit organization which is a licensing/certification partner with CMS, such as the American Institute of Healthcare Compliance.

Ensure All Audits are in Alignment with Organizational Objectives

An effective audit program should assist with the ongoing evaluation of the organization’s compliance program and demonstrate the level of risk for mitigation purposes. Ideally, an organization would regularly complete a risk assessment that helps define the work plan for the audits or monitoring. Without a work plan, an organization might not demonstrate it’s aware of the risks impacting it and focus attention on lower-risk areas.

To audit where your organization is on the OIG risk spectrum, you should review your compliance program's effectiveness by auditing its seven core elements and assessing your exposure to risks like fraud, waste, and abuse. The seven elements recommended by the OIG are:

  1. Written Policies and Procedures
  2. Compliance Leadership and Oversight
  3. Training and Education
  4. Effective Lines of Communication
  5. Enforcing Standards: Consequences and Incentives
  6. Risk Assessment, Auditing, and Monitoring
  7. Responding to Detected Offenses and Developing Corrective Action Initiatives

Start by evaluating your internal controls and policies, checking for potential violations, and using risk assessment tools that consider both the likelihood and impact of risks. These audits help identify areas for improvement and ensure you are not on a path that could lead to severe consequences such as OIG exclusion or a Corporate Integrity Agreement.

Audit for Quality Assurance to Improve Patient Care

The Centers for Medicare & Medicaid Services (CMS) Quality Assurance and Performance Improvement (QAPI) is a data-driven, proactive approach that combines Quality Assurance (QA) and Performance Improvement (PI) to maintain and improve care standards in healthcare facilities like nursing homes.

QA ensures that care meets established standards, while PI focuses on continuously enhancing processes to prevent issues and improve outcomes and resident quality of life. A key framework for QAPI includes five core elements: Design and Scope, Governance and Leadership, Feedback/Data Systems/Monitoring, Performance Improvement Projects, and Systematic Analysis and Action.

Element 1: Design and Scope

A QAPI program must be ongoing and comprehensive, dealing with the full range of services offered by the facility, including the full range of departments. When fully implemented, the QAPI program should address all systems of care and management practices, and should always include clinical care, quality of life, and resident choice. It aims for safety and high quality with all clinical interventions while emphasizing autonomy and choice in daily life for residents (or resident’s agents). It utilizes the best available evidence to define and measure goals. Nursing homes will have in place a written QAPI plan adhering to these principles.

Element 2: Governance and Leadership

The governing body and/or administration of the nursing home develops a culture that involves leadership seeking input from facility staff, residents, and their families and/or representatives. The governing body assures adequate resources exist to conduct QAPI efforts. This includes designating one or more people to be accountable for QAPI; developing leadership and facility-wide training on QAPI; and ensuring staff time, equipment, and technical training as needed.

The Governing Body should foster a culture where QAPI is a priority by ensuring that policies are developed to sustain QAPI despite changes in personnel and turnover. Their responsibilities include, setting expectations around safety, quality, rights, choice, and respect by balancing safety with resident-centered rights and choice. The governing body ensures staff accountability, while creating an atmosphere where staff is comfortable identifying and reporting quality problems as well as opportunities for improvement.

Element 3: Feedback, Data Systems and Monitoring

The facility puts systems in place to monitor care and services, drawing data from multiple sources. Feedback systems actively incorporate input from staff, residents, families, and others as appropriate. This element includes using Performance Indicators to monitor a wide range of care processes and outcomes and reviewing findings against benchmarks and/or targets the facility has established for performance. It also includes tracking, investigating, and monitoring Adverse Events that must be investigated every time they occur, and action plans implemented to prevent recurrences.

Element 4: Performance Improvement Projects (PIPs)

A Performance Improvement Project (PIP) is a concentrated effort on a particular problem in one area of the facility or facility wide; it involves gathering information systematically to clarify issues or problems and intervening for improvements. The facility conducts PIPs to examine and improve care or services in areas that the facility identifies as needing attention. Areas that need attention will vary depending on the type of facility and the unique scope of services they provide.

Element 5: Systematic Analysis and Systemic Action

The facility uses a systematic approach to determine when in-depth analysis is needed to fully understand the problem, its causes, and implications of a change. The facility uses a thorough and highly organized/structured approach to determine whether and how identified problems may be caused or exacerbated by the way care and services are organized or delivered.

  • Additionally, facilities will be expected to develop policies and procedures and demonstrate proficiency in the use of Root Cause Analysis.
  • Systemic Actions look comprehensively across all involved systems to prevent future events and promote sustained improvement. This element includes a focus on continual learning and continuous improvement.

QAPI amounts to much more than a provision in Federal statute or regulation; it represents an ongoing, organized method of doing business to achieve optimum results, involving all levels of an organization.

Conclusion

The OIG recommends an organization develop a set of monitors or warning indicators to alert it to risks that require mitigation. This may be in the form of data mining or reported concerns from employees or patients. These indicators can assist in identifying a risk when it occurs instead of years after the incident.

Adherence to OIG guidance is considered a basic best practice. An effective compliance program, which includes risk assessments and audits, help meet requirements of the Federal Sentencing Guidelines and is viewed favorably by enforcement authorities like the Department of Justice (DOJ).

About the AIHC Education Department

The American Institute of Healthcare Compliance (AIHC) Education Department provides classroom and web-based training and certification for healthcare administrators and professionals. It includes an enrollment department that processes registrations, and a research and development arm focused on creating new educational products. Learn more about short course and certification offerings in addition to free and low-priced Continuing Education Unit (CEU) certification renewal single short courses or CEU packages. Visit our website https://dev-main.aihc-assn.org/

References

  • Auditing for Compliance certification course with the American Institute of Healthcare Compliance
  • Exclusions Program with the Office of Inspector General
  • Fraud Risk and Heightened Scrutiny with the Office of Inspector General
  • Quality Assurance and Performance Improvement (QAPI) with the Centers for Medicare & Medicaid Services

Copyright © 2025 American Institute of Healthcare Compliance All Rights Reserved

Read More
Healthcare Revenue Cycle Compliance
Billing/RCM

Root Cause of Medicare Claim Denials

Written By Teresa Bolden, CPC, CPMA, CEMC, CHBS, Medicare Compliance Consultant   

 

Root Cause Analysis (RCA) is an important claims management tool to improve billing compliance.  It is a systematic problem-solving technique used to identify the underlying causes of a particular issue or problem, rather than addressing only its symptoms. It involves a structured approach to investigating and understanding why something happened, with the goal of preventing its recurrence. Applying RCA to analyze how and why claims are denied not only improves your bottom line, but reduces future denials, improves the organization’s ability to push-back on inappropriate denials and increases billing compliance through a documented process.

Introduction

Accuracy must be the focus of documentation, coding and billing compliance efforts.  Analyzing denial trends which may exist in your Accounts Receivable (A/R) is the place to start.  But understanding how Centers for Medicare & Medicaid (CMS) views fraud versus abuse is equally important.  Download the CMS Medicare Fraud & Abuse: Prevent, Detect, Report Booklet for more information, but in short note the following:

When you submit a claim for services provided to a Medicare beneficiary, you are filing a bill with the Federal government and certifying you earned the payment requested and complied with the billing requirements. If you knew or should have known the submitted claim was false, then the attempt to collect payment is illegal. When Medicare denies a claim, review documentation and billing to evaluate whether it can be appealed. Examples of improper claims which should not be appealed, but written off and are subject to further investigation by CMS often include:

  • Billing codes that reflect a more severe illness than actually existed or a more expensive treatment than was provided
  • Billing medically unnecessary services
  • Billing services not provided
  • Billing services performed by an improperly supervised or unqualified employee
  • Billing services performed by an employee excluded from participation in the Federal health care programs
  • Billing services of such low quality they are virtually worthless
  • Billing separately for services already included in a global fee, like billing an evaluation and management service the day after surgery

CMS and the Office of Inspector General (OIG) expect providers and physicians treating Medicare beneficiaries to establish an effective compliance program. Establishing and following a compliance program helps physicians avoid fraudulent activities and submit accurate claims. The following seven components provide a solid basis for a physician practice compliance program:

  1. Conduct internal monitoring and auditing
  2. Implement compliance and practice standards
  3. Designate a compliance officer or contact
  4. Conduct appropriate training and education
  5. Respond appropriately to detected offenses and develop corrective action
  6. Develop open lines of communication with employees
  7. Enforce disciplinary standards through well-publicized guidelines

Understanding Medicare Claim Denials

Medicare claim denials can be a significant source of frustration and financial strain for the healthcare community. While seasoned coding and billing specialists are knowledgeable about root causes for common denials, they too find it challenging at times to dodge the obstacles that result in claim denial. To begin the RCA process, it is vital to gain an understanding of how the payer determines a denial.  CMS publishes the most common reasons for Medicare denials by category as follows:

  1. Duplicate claim/service
  2. Bundled service/procedure
  3. Care covered by another payer
  4. Medical necessity
  5. Non-covered service/item

Understanding root causes for claim denials is crucial for improving claim acceptance rates and ensuring timely reimbursement. Below we explore the most common reasons for Medicare claim denials and insights into how to avoid unnecessary denials

1.  Duplicate claim/service.

Duplicate claim denials continue to be one of the top billing errors among all Medicare Administrative Contractors (MACs). A duplicate denial indicates that more than one claim was submitted for the same service, for the same patient, for the same date of service. In most instances, the claim was already processed and paid. While some claims are exact duplicates of previously submitted claims, some services are denied as duplicates for other reasons. The following reason and remark codes are examples of common duplicate claim/service denial messages:

Reason CODE

Remark Code

Definition

18

Duplicate claim/service.

M86

Service denied because payment already made for same/similar procedure within set time frame.

N20

Service not payable with other service rendered on the same date.

N327

Your claim for a referred or purchased service cannot be paid because payment has already been made for this same service to another provider by a payment contractor representing the payer.

N522

Duplicate of a claim processed, or to be processed, as a crossover claim.

AVOID DENIALS FOR EXACT DUPLICATES 

  • Allow 30 days from the claim receipt date before submitting a subsequent claim for the same service(s).
  • Use the MACs free online portal or Interactive Voice Response (IVR) to check the status of the initial claim before submitting a subsequent claim.
  • Investigate the reason for denial, rather than simply resubmitting the claim. Some physicians/QHPs will refile a claim to correct a previously denied claim. This resubmission can cause an unnecessary duplicate denial when the initial claim processed correctly.
  • Correct the following clerical errors through your MAC’s IVR or online portal:
    • Change the referring provider name and National Provider Identifier (NPI).
      • The rendering provider’s NPI may not be changed.
    • Change the number of services or units.  
    • Add or change claim diagnosis codes.
    • Add, change or delete eligible modifiers.
      • Excluded modifiers are: 22, 24, 52, 53, 55, 62, 66, 80, 81, EA, GA, GX, GY
    • Change the procedure code.
    • Change the date of service.
    • Change the place of service.
    • Change the billed amount.

A physician or other QHP may perform multiple procedures or “repeat procedures,” to the same patient on a single day. All services provided to the same patient, by the same physician/QHP, on the same date of service should be billed on the same claim.

AVOID DENIALS FOR REPEATED PROCEDURES

  • When appropriate, use a unit of service multiplier rather than billing the same CPT/HCPCS code on multiple lines.
  • Drug codes - bill the HCPCS code for drugs according to the dosage in the code’ description and add a multiplier on the claim to show the appropriate dosage. For example, the HCPCS descriptor states 1 mg and 4 mg are administered, the drug should be billed with 4 units of service (UOS).
  • Drug administration fee – bill one UOS for each intramuscular administration of therapeutic drugs on one line (i.e., 96372). The UOS billed should equal the number of separate injections.
  • Use one of the following modifiers to report services or procedures repeated on the same day:
    • 76 – Procedure or service was repeated subsequent to the original procedure.
    • 77 – Repeat procedure or service by another physician or other QHP subsequent to the original procedure.
    • 91 – Repeat clinical diagnostic laboratory test.

NOTE: Include a narrative description indicating the reason for the repeated procedure in item 19 of the 1500 claim form or the electronic equivalent.

2.  Bundled service/procedure.

There are several scenarios in which a service or procedure does not receive separate reimbursement because payment for it is included in Medicare’s payment for another service or procedure. The most common form errors falling under the category of bundling denials identified by CMS:

  • Items are always bundled;
  • Lack of accurately applying the National Correct Coding Initiative (NCCI) edits; and
  • Errors made related to global surgery claims;

Always bundled. Some services/procedures are “always bundled” for Medicare purposes and never receive separate reimbursement, even from the patient. Those services/procedures have a status indicator of “B” or “P” in the Medicare Physician Fee Schedule (MPFS) Relative Value File (Addendum B of the MPFS Final Rule). The common reason and remark codes used for always bundled services/procedures are:

Reason CODE

Remark Code

Definition

125

Submission/billing error(s)

N19

Procedure code incidental to primary procedure.

M15

Separately billed services/tests have been bundled as they are considered components of the same procedure. Separate payment is not allowed.

M80

Not covered when performed during the same session/date as a previously processed service for the patient.

AVOID ALWAYS BUNDLED DENIALS

  • Identify the status indicator for all services provided by reviewing the MPFS Relative Value File annually. Flag services/procedures that have a status indicator of “B” or “P” as non-billable charges.

National Correct Coding Initiative (NCCI) Edits. The Centers for Medicare & Medicaid Services (CMS) developed the NCCI program to promote national correct coding of Medicare Part B claims. The purpose of the NCCI Procedure to Procedure (PTP) edits is to prevent improper payment when incorrect code combinations are billed. The NCCI contains one table of edits for physicians and other qualified healthcare professionals (QHPs) and one table of edits for outpatient hospital services. The NCCI PTP edits are available free of charge from the CMS website.

The CMS also developed the NCCI Medically Unlikely Edits (MUE) program to prevent improper payments when services are reported with incorrect units of service. The NCCI MUEs assigned to each CPT/HCPCS code are in the NCCI PTP edit table.

The common reason and remark codes for NCCI bundled services/procedures are:

Reason CODE

Remark Code

Definition

97

The benefit for this service is included in the payment/allowance for another procedure or service that has already been paid.

4

Procedure code is inconsistent with the modifier, or a required modifier is missing.

M80

Not covered when performed during the same session/date as a previously processed service for the patient.

M362

The number of days or units of service exceed our acceptable maximum.

AVOID NCCI BUNDLED DENIALS

  • Download the most recent PTP edits.
    • Locate the code pair in the Column1/Column 2 List. The Column 2 code is considered a component of the Column 1 code.
    • Review Column F to determine if a modifier may be appropriate for the situation.
  • Review the NCCI Policy Manual that is available in the NCCI section of the CMS website. The policy manual provides additional details regarding PTP edits along with exceptions and instructions for using modifiers.
  • Use encoder software to identify bundled services and modifier opportunities.

Global Surgery Edits. The global surgical package, also called global surgery, includes all necessary services normally provided by a physician (or members of the same group with the same specialty) before, during, and after a procedure. Medicare physicians in the same group practice, with the same specialty, must bill and accept payment as though they are a single physician. Global surgery applies in any setting, including an inpatient hospital, outpatient hospital, ambulatory surgical center (ASC), and physician’s office.

The Medicare physician fee schedule (MPFS) includes all procedure codes and global surgery indicators. The global surgery payment rules apply to procedure codes with global surgery indicators 000, 010, 090 and sometimes, YYY. Definitions for the most common global surgery indicators are as follows:

  • 000 codes identify endoscopies and some minor surgical procedures. The Medicare allowable includes the cost of the related E/M service provided on the same day.
  • 010 codes identify other minor procedures. The Medicare allowable includes the cost of the related E/M service on the same day, plus 10 days following the procedure.
  • 090 codes identify major surgeries. The Medicare allowable includes the cost of the related E/M service provided the day before the surgery, day of the surgery, plus 90 day following surgery.

NOTE: Refer to the CMS publication of Global Surgery (MLN907166 December 2023) for complete guidelines and exceptions to global surgery rules.

The common reason and remark codes for bundled services due to global surgery are:

Reason CODE

Remark Code

Definition

97

The benefit for this service is included in the payment/allowance for another procedure or service that has already been paid.

M80

Not covered when performed during the same session/date as a previously processed service for the patient.

M144

The cost of care before and after the surgery or procedure is included in the approved amount for that service.

N20

Service not payable with other service rendered on the same date.

AVOID GLOBAL SURGERY BUNDLED DENIALS

  • Bill E/M service(s) provided during the postoperative period for a reason(s) unrelated to the original procedure, with modifier 24.
  • A significant, separately identifiable E/M service provided on the same day as a minor procedure, may be billed with modifier 25.
    • NOTE: This one of the most commonly misused modifiers. Refer to your local MACs instructions for using modifier 25. According to Medicare, the decision for surgery is always included in the allowance for a minor surgical procedure. (Reference: IOM Publication 100-04 Chapter 12.40.1.B)
  • Critical care provided on the same day or during the postoperative period that is unrelated to the surgical procedure should be billed with modifier FT.
  • When the need to perform major surgery within 24 hours is decided during an E/M service, bill the E/M with modifier 57 (decision for surgery).
  • It may be necessary to indicate that another procedure was performed during the postoperative period of the initial procedure. When the patient returns to the operative suite to address postoperative complications, bill the unplanned surgical procedure with modifier 78.
  • An unrelated surgical procedure(s) performed during the postoperative period of another procedure should be billed with modifier 79.
  • It may be necessary to indicate that the performance of a procedure or service during the postoperative period was (a) planned or anticipated (staged); (b) more extensive than the original procedure; or (c) for therapy following a surgical procedure. When one of these circumstances apply, bill the procedure with modifier 58.

3.  Claims sent to the wrong payer/contractor.

Medicare law and regulations require all entities that bill Medicare for services or items given to Medicare beneficiaries to decide whether Medicare is the primary payer for those services or items before submitting a claim to Medicare (Reference: Section 1862(b)(2) of the Social Security Act and regulations at 42 CF 489.20g).

Medicare Secondary payer (MSP) provisions protect Medicare from paying when another entity should pay first. Medicare may be secondary if the patient falls under any of the following reasons:

MSP Type

Secondary Coverage Reason

Type 12

The patient is an aged worker or spouse with an employer group health plan of more than 20 employees.

Type 13

Is covered under an End Stage Renal Disease (ESRD) coordination period, which is typically the first 30 months.

Type 14 or 47

Is covered under a no-fault plan, which usually includes any liability or auto claims.

Type 15

Is covered under a workers’ compensation claim.

Type 42

Is covered under a Veterans Administration plan and is not being attended within a VA facility or a VA physician.

Type 43

Is disabled and the employer’s group plan has 100 or more employees.

NOTE: Medicare’s publication of Medicare Secondary Payer MLN006903 dated October 2023 includes common MSP Coverage Situations

There are several situations in which a local Medicare Administrative Contractor (MAC) is not the appropriate payer/contractor to process a claim for a Medicare patient. Besides traditional Medicare, Congress created a Medicare Advantage option that allows private insurance companies offer coverage to people with Medicare, giving them more choices. These Medicare Advantage options (sometimes called Part C) include:

  • Medicare Health Maintenance Organizations
  • Preferred Provider Organizations
  • Private Fee-for-Service Plans
  • Medicare Medical Savings Account Plans
  • Medicare Special Needs Plans

The common reason and remark codes for claims sent to the wrong payer/contractor are:

Reason CODE

Remark Code

Definition

22

This care may be covered by another payer per coordination of benefits.

24

Charges are covered under a capitation agreement/managed care plan.

109

Claim/service not covered by this payer contractor. You must send the claim/service to the correct payer/contractor.

MA92

Missing plan information for other insurance

N193

Alert specific federal/state/local program may cover this service.

AVOID INCORRECT PAYER DENIALS

  • Collect full patient health information upon each office visit, outpatient visit, and hospital admission.
  • Patients that elect coverage through a Medicare Advantage (MA) plan still keep their original red, white and blue Medicare cards. Be sure to ask to see all of their insurance cards.
    • Patients may elect new plans each year. In some situations, coverage may change in the middle of a calendar year.
  • Find the primary payer before submission of a claim, and bill the proper responsible payer(s) for related services.
  • Use the MAC’s IVR to verify whether Medicare is primary or secondary for specific patients prior to submitting claims.
  • For multiple services, bill each responsible payer(s) separately.
  • Do not bill for treatment provided for accident-related services and non-accident-related services on the same claim. Send separate claims to Medicare: one claim for services related to the accident and another claim for services not related to the accident.
  • Always use specific diagnosis codes related to an accident or injury. Doing so will promote correct and prompt payment. Do not forget to report ICD-10-CM external cause codes.
  • Download and review the quick reference table for common MSP coverage situations in MLN006903 dated October 2023.

4.  Not Covered Due to Medical Necessity

Section 1862(a)(1) of the Social Security Act (the Act) states no Medicare payment shall be made for expenses incurred for items or services that “are not reasonable and necessary for the diagnosis or treatment of illness or injury or to improve the functioning of a malformed body member.” To that end, CMS developed National Coverage Determinations (NCDs) to determine if a specific item or service is covered by Medicare nationally. Each NCD is based on evidence, limiting coverage to items and services that are considered “reasonable and necessary” for treating or diagnosing an illness or injury. NCDs can be found online in Internet Only Manual (IOM) Publication 100-03.

Some services are processed according to a Local Coverage Determination (LCD) and its accompanying Billing/Coding Article. These resources identify coverage criteria, frequency limitations, documentation requirements, coding guidelines and medical necessity. LCDs are decisions made by MACs that apply to services provided to Medicare patients within the specific jurisdiction that the MAC oversees. The common reason and remark codes for medical necessity denials are:

Reason CODE

Remark Code

Definition

50

These are non-covered services because this is not deemed a “medical necessity: by the payer.

N115

This decision was based on a Local Coverage Determination (LCD).

AVOID MEDICAL NECESSITY DENIALS

  • Stay up-to-date with Medicare’s coverage policies and guidelines.
  • Ensure that medical records comprehensively document the patient’s condition and the necessity of the services provided.
  • Use encoder software to identify medical necessity concerns.
  • If a patient decides to receive the item/service that Medicare considers not medically necessary, be sure to obtain an Advance Beneficiary Notice (ABN) before providing the item or service.
    • NOTE: The CMS developed an Advance Beneficiary Notice of Non-coverage Tutorial (MLN909183 May 2023).

5.  Non-Covered Service/Item

Some services are statutorily excluded from Medicare coverage. Examples include custodial care, cosmetic surgery, personal comfort items and services, items and services required because of war, routine or annual physical checkups (with certain exceptions). In general, healthcare providers are not required to submit claims to Medicare for statutorily excluded services. There are times, however, when the patient requests the service(s) to be submitted in order to obtain a denial for secondary insurance purposes. In this case, submit statutorily excluded services with modifier –GY (item or service statutorily excluded, does not meet the definition of any Medicare benefit or, for non-Medicare insurers, is not a contract benefit). The common reason and remark codes for non-covered items/services are:

Reason CODE

Remark Code

Definition

96

Non-covered charges.

N425

Statutorily excluded service(s).

Cell

N431

Not covered with this procedure.

AVOID UNNECESSARY NON-COVERED SERVICE/ITEM DENIALS

  • Download and review CMS publication of Items & Services Not Covered under Medicare (MLN906765 June 2022).
  • Notify the patient that the item/service is statutorily excluded from coverage.
    • NOTE: The ABN may be provided to Medicare beneficiaries as a courtesy, to inform them of their financial responsibility for services that are statutorily excluded from Medicare coverage. Healthcare providers are not required to use an ABN to notify patients about statutorily excluded items/services.
  • Do not bill statutorily excluded services to Medicare unless the patient requests it.
  • Append modifier –GY to statutorily excluded services that are billed to Medicare.

Conclusion

Maintain accurate and complete medical records and documentation of the services you provide. This ensures improved coordination of care, quality and improves your ability to appeal and have denied claims overturned. Conduct pre-billing audits periodically to verify that documentation supports the claims you submit for payment. 

When your analysis identifies a trend in the type of denials, implement the RCA approach.  Learn more about Root Cause Analysis by enrolling in the Auditing for Compliance, online course offered by AIHC.

About the Author

Teresa Bolden,CPC, CPMA, CEMC, CHBS,  is a Medicare Compliance Consultant and serves on the AIHC Volunteer Education Committee.  Article edited by Joanne Byron, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, OHCC, ICDCT-CM/PCS of the American Institute of Healthcare Compliance (AIHC), a non-profit healthcare education organization.  

Copyright © 2024 American Institute of Healthcare Compliance All Rights Reserved

Read More
Healthcare Revenue Cycle Compliance
Billing/RCM

Why Data Analytics are Critical in a Value-Based Care (VBC) Environment

Written by: Corliss Collins, BSHIM, RHIT, CRCR, CSM, CCA, CBCS, CPDC, Sheryn Honest, MBA, MLS, CHCO, CHA, CPC, Wendy Bartko, CPC, CEMC, CPMA, CPCO, CRC, CHA, CMDP, CIFHA 

This article on Value-Based Care (VBC) addresses the importance of understanding the basics of data analytics to ensure C-Suite Executives have accurate information to make sound business decisions when engaging in new payment methodologies.  We recommend reading Leadership in a Value-Based Care (VBC) Environment in addition to this article. 

Why this Trend of Value-Based Care?

A 2022 report from the Commonwealth Fund U.S. Health Care from a Global Perspective, 2022: Accelerating Spending, Worsening Outcomes indicates that in 2021 the U.S. spent 17.8 percent of the gross domestic product (GDP) on healthcare, which was almost two times the average of other high-income countries, while the health outcomes in the U.S. are worse than those of our peer nations across the world. Previous attempts to improve care and reduce costs has failed, thus, health care in the United States is shifting to a Value-Based Care model.

Over the past decades, the traditional method of reimbursing providers was in a fee-for-service (FFS) model. A provider would see a patient, document the visit, and select the procedure code(s) for the service(s). A claim would be generated and submitted to the payer. The payer would reimburse the provider according to their FFS contract, which typically had an allowable amount for each billable procedure code. Therefore, the provider would be reimbursed a fee for each service (CPT code) provided.  As the cost of providing care grew, payers started instituting methods to curb expenses and how claims were paid.  Payers started shifting to a shared-responsibility for expenses and expecting improved quality in the delivery and availability of care to their beneficiaries.

Medicare changed reimbursement methodology in the 1980s by introducing Relative Value Units (RVUs) and the RBRVS (Resource-Based Relative Value System) for physician reimbursement.  Prior to this time, commercial carriers were already pushing HMOs (health maintenance organizations) and capitation contracts with physician networks or instituting "reasonable and customary charges" requiring physicians to collect data to negotiate reasonable contracts.  Hospital reimbursement also changed.  In 1983 Medicare shifted to the inpatient Prospective Payment System (PPS) and DRGs (Diagnostic Related Groups) and only paying a limited number of days to the hospital regardless of the actual length of stay.  Medicare also encouraged improved hospital performance through the Hospital-Acquired Condition (HAC) Reduction Program, which is a Medicare value-based purchasing program that reduces payments to hospitals based on their performance on measures of hospital-acquired conditions (HACs). The HAC Reduction Program encourages hospitals to improve patients’ safety and implement best practices to reduce their rates of infections associated with health care.  During this time (1980s - early 1990s) health spending increased at an accelerated which can be attributed to expensive new medical technologies and the curtailing of the ambitious HMO-promoting programs of the 1970s.

Those providers who were not prepared to manage the new reimbursement often resorted to “enhancing” revenue through “creative” means.  As payers investigated insurance fraud, waste and abuse, increased oversight was implemented by creating Special Investigation Units (SIU) by many carriers and additional oversight by the Office of Inspector General (OIG) and stricter laws, such as the Antikickback Statutes, False Claims Act, Physician Self-Referral Law (Stark) with the Health Insurance Portability and Accountability Act of 1996 (HIPAA) establishing a national Health Care Fraud and Abuse Control Program (HCFAC or the Program) under the joint direction of the Attorney General and the Secretary of the Department of Health and Human Services (HHS).

As more and more potential and real fraud, waste, and abuse was uncovered in the FFS arena, it was also discovered that patient outcomes were less than stellar. The poor quality of care, inefficiencies, and total cost to the U.S. healthcare system were exorbitant.

Centers for Medicare & Medicaid Services (CMS)

The Centers for Medicare & Medicaid Services (CMS) is using value-based programs to reward health care providers with incentive payments for the quality of care they provide to Medicare beneficiaries & support a three-part aim including:

  • Better care for individuals
  • Better health for populations
  • Lower costs

2004 Risk Adjustment Implemented by CMS

Hierarchical condition category (HCC) coding is a risk-adjustment model originally designed to estimate future health care costs for patients. The Centers for Medicare & Medicaid Services (CMS) HCC model was initiated in 2004 and is becoming increasingly prevalent as the environment shifts to value-based payment models.  Risk adjustment is a reimbursement method originally designed to estimate future health care costs using Hierarchical Condition Category (HCC) coding which are to be submitted annually beginning January 1st.

Please note that accuracy of data collection is critical.  Please reference the list of terms below under “Metrics”.  Data quality, accuracy, completeness, consistency and predictive analytics all apply to HCC.

Value Based Programs are important in helping to move toward paying providers based on the quality rather than the quantity of care provided.  The 5 original CMS Value based programs:

  • End-Stage Renal Disease Quality Incentive Program (ESRD QIP)
  • Hospital Value Based Purchasing Program (HVBP)
  • Hospital Readmission Reduction Program (HRRP)
  • Value Modifier Program (Physician Value Based Modifier/PVBM)
  • Hospital Acquired Conditions Reduction Program (HAC)

Two additional programs:

  • Skilled Nursing Facility Value -Based Purchasing (SNF-VBP)
  • Home Health Value Based Purchasing (HHVBP)

Going back to at least 2008, different legislation including MIPPA (Medicare Improvements for Patients and Providers Act) was passed. These different Acts initiated the testing of alternate forms of delivering care and payment methodologies. The image below is the timeline from CMS.GOV regarding Medicare specific value-based programs and a more aggressive government initiative to institute reimbursement for Value-Based Care (VBC).

VBC is the current attempt to undo the perfect storm in healthcare. VBC is patient-focused and looks to increase the quality, coordination, and access to care, while reducing the cost of care. There are four types of prevalent VBC models:

  1. Pay for Performance can be a combination of FFS reimbursement plus additional incentives for providers/facilities to meet specified quality metrics. Overtime, metrics have been developed by many organizations including, the National Quality Forum (NQF), the Joint Commission, the National Committee for Quality Assurance (NCQA), the Agency for Health Care Research and Quality (AHRQ), and the American Medical Association (AMA).
  2. Bundled payments group together a service, procedure, hospital stay, or condition along with multiple service providers are needed to perform the service (e.g., hospital, outpatient provider group, specialty care, radiology, laboratory). A dollar amount is allocated for the service and any cost containing savings are distributed back to the service providers. These service providers are required to coordinate care amongst each other, in order to maximize cost containment. If the cost exceeds the allocated amount, then the services providers would be responsible for covering the exceeded cost.
  3. Shared Savings (e.g., ACO) combines quality care outcomes with reduced healthcare spending by having collaborative and coordinated care amongst the service providers. There is more financial risk for service providers participating in Share Savings programs, but there is also more financial incentive when quality and cost-efficiency are maximized.
  4. Capitation (e.g., MA/HMO) is typically used by Health Maintenance Organizations and Medicare Advantage Organizations. A per member per month (PMPM) reimbursement is established by the insurance company and the service provider has to manage all care within the PMPM payment received. The patient’s care is managed by a gatekeeper (aka Primary Care Provider (PCP)) who coordinates all care (ideally in an outpatient setting) amongst other in-network service providers.
  • This is the riskiest model since there is both upside and downside risk that the gatekeeper is responsible for.
  • Reimbursement can fluctuate based on the (good or poor) health of the patient. Diagnosis codes submitted to the payer determine reimbursement levels…the more ill the patient (with chronic disease(s)), the more the reimbursement allocated to the patient.

In all of these models, knowing how your business is running is key to managing outcomes. The main way of knowing how your business is running is through understanding your numbers. Having relevant, accurate, and timely data analytics is one of the most important keys to success in any healthcare organization.

Metrics

Data analytics metrics are used to assess the performance, effectiveness, and impact of data analytics processes, projects, and initiatives. These metrics help organizations understand how well they use data to make informed decisions. Testing the accuracy of the data your organization is collecting is critical.  Inaccurate data could cause C-Suite Executives to lose confidence in your abilities, whether you are in-house working as part of the workforce in the finance department or a consultant.

Specific metrics may vary depending on the goals of the analytics project and the nature of the data being analyzed. Please see some of the most commonly used data analytics metrics below:

Key Performance Indicators (KPIs) are essential metrics that directly align with an organization's strategic goals. They can be financial, operational, or customer-focused. Examples include revenue growth, customer retention rate, and cost reduction.

Data Quality: Metrics related to data quality assess the accuracy, completeness, consistency, and reliability of the data being analyzed. Examples include data accuracy, data completeness, and data consistency.

Data Processing Time: This metric measures the time it takes to collect, clean, transform, and load (ETL) data before it can be used for analysis. Reducing data processing time can lead to more timely insights.

Data Accuracy: It quantifies how precise and error-free the data is. High data accuracy is crucial for making reliable decisions.

Data Completeness: This metric evaluates the proportion of data that is present compared to the total expected data. Incomplete data can lead to biased or unreliable results.

Data Consistency: Data consistency measures how well data is aligned and harmonized across different sources and systems. Inconsistent data can lead to discrepancies and confusion.

Data Volume: The amount of data being processed or stored. It can help determine storage and processing needs.

Data Velocity: This metric assesses how quickly data is generated, collected, and processed. It's particularly relevant for real-time or near-real-time analytics.

Data Variety: Data analytics often involve different data types (structured, unstructured, semi-structured). Measuring data variety helps ensure that diverse data sources are appropriately managed.

Data Latency: The time delay between data collection and its availability for analysis. Low-latency data is crucial for real-time analytics.

Data Retention Rate: Measures how long data is stored and maintained for future analysis. It's important for compliance and historical trend analysis.

Data Accessibility: This metric gauges how easily data can be accessed and utilized by analysts and decision-makers.

Data Security and Compliance: Metrics related to data security and compliance assess the protection of sensitive data and adherence to regulatory requirements, like GDPR or HIPAA.

Data Usage and Adoption: Measures how frequently and effectively data analytics tools and insights are used by the intended audience within the organization.

ROI (Return on Investment): Evaluates the value generated from data analytics initiatives compared to the resources and costs invested.

User Engagement and Satisfaction: Metrics related to user experience and satisfaction with data analytics tools and dashboards.

Model Accuracy and Performance: For machine learning and predictive analytics, these metrics assess how well models perform in making accurate predictions.

Data Visualization Effectiveness: Measures the clarity and usefulness of data visualizations in conveying insights.

Data Governance Metrics: These include metrics related to data cataloging, metadata management, and data stewardship practices.

Data-driven Decision-Making: Metrics that track how data analytics influences and improves organizational decision-making.

It's crucial to select and track the metrics that align with the specific objectives and context of your data analytics projects. Regularly reviewing and analyzing these metrics can help organizations make data-driven improvements and achieve better results.

Conclusion

We can count on payers continuing to shift the burden of cost to providers.  And, it is expected that providers will continue to strive to provide quality and safe care at a reasonable cost.  However, with rising inflation, sky-rocketing expenses for the latest technology and the use of Artificial Intelligence (AI) integrated into our health care systems (which doesn’t come cheap), the ONLY way providers will financially survive a VBC environment is to negotiate appropriate, reasonable terms with payers based on accurate and reliable data. 

This article is written by members of the AIHC Volunteer Education Committee.  AIHC is a non-profit organization.  We value our members, credentialed professionals and greatly appreciate the talents offered by our member volunteers!

Copyright © 2023 American Institute of Healthcare Compliance All Rights Reserved

Read More