Affiliate disclosure

Book titles on this page link to Amazon. As an Amazon Associate, DataField.Dev earns from qualifying purchases — at no additional cost to you.

Chapter 37 — Further Reading

The orientation for this chapter's sources. Almost everything that governs how you will be audited is free, federal, and published — and almost nobody reads it until a letter arrives. Two documents in Tier 1 below are worth putting on a calendar rather than a shelf: the OIG Work Plan, which tells you what is about to be examined, and your own RAC's approved-issues list, which tells you what is about to be reviewed in your region. Between them they scope an entire year of internal audit for the price of an hour a quarter.

Everything in Tier 2 changes on a schedule. Nothing in this book's own worked figures should be quoted as current — they exist to teach a structure, and the structure is what transfers.


Tier 1 — Canonical: the rules, the manuals, and the programs

  • Medicare Program Integrity Manual, CMS Publication 100-08. The single most useful document in this chapter. It is what a Medicare reviewer is working from. Chapter 3 covers verifying potential errors, the levels of medical review, prepayment and postpayment review, and corrective action. Chapter 8 is the statistical sampling and extrapolation chapter — the universe, the sampling frame, sample-size determination, the estimation methods, and the documentation the contractor must produce. If you read one thing behind §37.6, read Chapter 8. Free, and revised by change request.

  • Social Security Act §1893(f)(3) — the statutory limit on extrapolation: a contractor may use it only on a determination of a sustained or high level of payment error, or where documented educational intervention has failed. It is the first question a response letter should test.

  • CMS's Medicare Fee-for-Service Recovery Audit Program pages, and each Recovery Audit Contractor's own approved-issues list. The issues list is published in advance, by region and provider type, and is a literal forecast of the next review. Also here: current record-request limits, the discussion-period rules, and the contract structure Case Study 1 describes.

  • CMS's Targeted Probe and Educate program page. Round structure, sample sizes, the education component, and what happens after the final round. Verify the current parameters; they have been adjusted.

  • CMS's Comprehensive Error Rate Testing (CERT) program pages and the annual Medicare Fee-for-Service supplemental improper payment data. The methodology, and — the part Case Study 2 turns on — the composition of the rate by error category. Read the composition, not the headline.

  • The Supplemental Medical Review Contractor's project pages (the current SMRC's site). What is under national review right now, and the findings from completed projects.

  • CMS's program integrity pages for the Unified Program Integrity Contractors, including jurisdiction maps and the payment-suspension authority. Know which UPIC covers you before you need to.

  • The OIG Work Plan (HHS Office of Inspector General). Continuously updated; each item states the issue, why it was opened, and an expected report date. Twenty minutes a quarter, and it scopes your risk-driven audit. The OIG's published reports themselves are the second half of this: they show the methodology an auditor used and the findings it produced.

  • The OIG Self-Disclosure Protocol, and CMS's Voluntary Self-Referral Disclosure Protocol (SRDP). Two different doors for two different problems — the SDP for conduct implicating civil monetary penalty authorities, the SRDP for the physician self-referral law only. Both are published with their content requirements, their eligibility limits, and their stated benefits. Read them before you need them, with counsel.

  • The sixty-day overpayment provision — Social Security Act §1128J(d), added by the Affordable Care Act — and the CMS regulations implementing it. The identification standard, what "reasonable diligence" requires, and the lookback period have all been revised by rulemaking. Verify the current text; this is the single most-changed provision in this chapter.

  • The False Claims Act, 31 U.S.C. §§ 3729–3733, including the reverse-false-claim provision that makes a retained overpayment actionable. Chapter 5 §5.3 owns the frame; this is the primary source.

  • OIG compliance program guidance — the physician-practice, hospital, and third-party-billing guidance, and the OIG's consolidated general compliance program guidance. The seven elements, and the auditing-and-monitoring expectations §37.1 and §37.2 rest on.

  • RAT-STATS (HHS OIG). The government's own statistical sampling software, free and public, with its companion documentation. A provider can use the same tool a contractor uses — which is what makes self-quantification under §37.9 practical rather than theoretical.

  • The Payment Integrity Information Act of 2019 and its predecessors, plus OMB's implementing guidance. The statutory definition of an improper payment that Case Study 2 reads closely — including underpayments and insufficient documentation.

  • Medicare Claims Processing Manual, CMS Publication 100-04, on demand letters, recoupment, rebuttal, and the interaction between an appeal and the recoupment clock. Chapter 31 §31.9 owns the operational workflow; this is where it is written down.


Tier 2 — Attributed: benchmarks, program history, and the moving parts

Everything in this tier is real and worth reading; the specific values in any of it expire.

  • Government Accountability Office reports on Medicare program integrity, the RAC program, and the improper payment estimate. The GAO is the most useful outside reader of this machinery: it describes designs, names the incentive problems, and is explicit that improper payments and fraud are distinct concepts. Search by program name rather than by report number, since the series continues.

  • The FY 2014 inpatient prospective payment system final rule and CMS's subsequent guidance on the two-midnight benchmark — the rule change that took short-stay inpatient status out of the RAC's hands and answered by rule a question that had been answered, inconsistently, by audit. Pairs with Chapter 16 §16.3.

  • CMS's published announcements of the Recovery Audit Program's next-round changes (the additional documentation request limits scaled to provider compliance, the discussion period, the contingency fee withheld until after the second appeal level, accuracy and overturn thresholds). These are the primary record behind Case Study 1's reform section.

  • AAPC and AHIMA audit and compliance material, including the Certified Professional Medical Auditor (CPMA) curriculum outline. Useful for what a credentialing body thinks an auditor must be able to do; Chapter 39 §39.3 places the credential.

  • Your own payer's provider manual and audit provisions. This is Tier 2 only because it varies by contract, and it is the most important item on this page for anyone whose commercial book is larger than its Medicare book. §37.5 and §37.6 both turn on the fact that a commercial special investigations unit's authority comes from your agreement, not from the Program Integrity Manual. Read the record-request rights, the lookback, the recoupment and offset terms, the reconsideration window, whether extrapolation is authorized at all, and the amendment mechanism. §37.8's operational conclusion is that you should read it on a schedule rather than when it matters.

  • State law on payer audits and extrapolation. A number of states now regulate commercial audit practice — notice requirements, lookback limits, and constraints on extrapolation. Whether any of it applies to you is a question for counsel, and the answer is entirely jurisdictional.

  • Published benchmarks for audit sample size and coder accuracy standards. These circulate widely and are worth knowing as orientation, not as authority. Insist on the denominator every time (§37.3): a "95% accuracy" benchmark is four different numbers, and a comparison between two organizations using different denominators is a comparison of definitions.


Tier 3 — Illustrative and constructed (this book's own material)

None of the following is a real record, a real organization, or a real figure. Every one is a constructed teaching example and is labeled as such where it appears.

  • Account 31-2245 — the unbundled shoulder claim; Ridgeview Orthopedic Surgery (constructed). The three claim lines, the modifier-59 macro, the 42-claim review, the \$612.40 average, the \$25,720.80 demand, and the eleven defensible-but-unprovable claims. Introduced in Chapter 5, coded in Chapter 17 §17.9, run edit-by-edit in Chapter 21 §21.9, and extrapolated here.
  • The counterfactual universe in §37.6 — 380 claims, a 42-claim sample, a constructed standard deviation and confidence multiplier, producing a point estimate of \$232,712.00 and a demand of \$204,489.40**, with the consistency variant at **\$227,582.00. Constructed to teach the shape of the arithmetic. The real methodology is in the Program Integrity Manual, Chapter 8.
  • Account 10-4471 — the Encounter; Northgate Family Medicine and Northfield Mutual Health Plan (both constructed). The March 14 office note is printed in full in Chapter 4 §4.10 as Figure 4.2; §37.11 audits the claim built from it.
  • Figures 37.1–37.4 — the audit plan, the scoring sheet, a payer's sampling methodology page, and two paragraphs of a response letter. All constructed.
  • The prepayment-review cash arithmetic in §37.4 and the internal-audit yield arithmetic in §37.2 — constructed teaching figures, footed, and useful only as shapes.

Where to go next

Chapter 38 is the technology: clinical documentation integrity, the compliant query and the leading one, and the engines that now read notes. It owns the query that closes the documentation gaps this chapter can only score. Chapter 39 is the credential, including the audit credential. And Chapter 40 assembles Account 10-4471 completely and answers the question this chapter deliberately left open.