The Types of Medicare Audits
When a Medicare records request or a demand letter arrives, the most useful first question is not “did we do something wrong” but “who is asking, and why.” Audit is a catch-all a billing office uses for very different things: a routine review to confirm a claim was payable, a post-payment hunt for improper payments, a statistical measurement of the whole program's error rate, and a fraud investigation. Each is run by a different Medicare contractor, under different authority, and each carries a different level of risk. This article maps the main types so a practice can tell them apart — because the response to a targeted educational review is not the response to a benefit-integrity investigation, and mistaking one for the other is how a manageable situation becomes a serious one.
Updated 16 min read
On this page
Key takeaways
- “Medicare audit” is not one thing. Different CMS contractors review claims for different purposes — medical review, improper-payment recovery, program error-rate measurement, and fraud investigation — and which contractor is asking tells a practice what is at stake.
- The Medicare Administrative Contractor (MAC) that pays a practice's claims also reviews them. Targeted Probe and Educate (TPE) is the MAC's data-driven review of a sample of a provider's claims paired with one-on-one education, across a limited number of rounds.
- The Recovery Audit program (RAC) is post-payment review to identify and correct improper payments — both overpayments and underpayments — and Recovery Auditors are paid on a contingency basis. The RAC identifies the issue; the MAC adjusts the claim and recovers the money.
- Comprehensive Error Rate Testing (CERT) measures the program's improper payment rate from a statistically valid random sample. It is measurement, not a targeted audit of a particular provider — though a sampled claim found in error is still corrected.
- Unified Program Integrity Contractors (UPICs) investigate potential fraud, waste, and abuse across Medicare and Medicaid. That is a more serious posture than an improper-payment review — it can lead to payment suspension and referral to the OIG.
- Most of these turn on documentation. A contractor's Additional Documentation Request (ADR) asks for the records behind a claim, and not responding generally means the claim is denied. A contractor's determination is appealable through Medicare's standard appeals process.
Why the type of audit matters
A practice that receives a letter from a Medicare contractor tends to file it under one word — “audit” — and to feel the same way about all of them. But CMS uses several distinct programs, run by different contractors, and they are not doing the same job. One is checking whether a claim met Medicare's coverage rules. One is looking for money that was paid in error, in either direction. One is measuring how accurately the whole program pays, using a random sample. One is investigating conduct that might be fraud. The letterhead, the contractor's name, and the reason stated in the notice are the fastest way to tell which kind of review a practice is in.
This sits in the Compliance and Regulations category because being reviewable — and being ready for it — is a compliance function. The programs below are the ones a physician practice, supplier, or facility billing Medicare fee-for-service is most likely to encounter. Medicare Advantage (Part C) plans run their own reviews under their own rules and are not covered here.
Prepayment and post-payment are the two basic timings
MAC medical review and Targeted Probe and Educate
The Medicare Administrative Contractor (MAC) is the contractor that processes and pays a practice's Medicare fee-for-service claims in its region — and the same contractor also reviews them. MAC medical review checks whether a claim met Medicare's requirements, most often whether the service was reasonable and necessary under national policy or the MAC's own Local Coverage Determination. Because the MAC is the payer, its review can be prepayment or post-payment.
The MAC review a practice is most likely to meet by name is Targeted Probe and Educate (TPE). Its purpose is not simply to claw back money — it is to reduce a provider's claim errors and appeals through one-on-one education. The MAC uses data analysis to select providers whose billing stands out: high claim-error rates, or patterns that differ from peers, on items and services that carry a high error rate and financial risk to Medicare. A provider whose claims are accurate and unremarkable is unlikely to be selected.
A probe of a sample of claims
The MAC reviews a sample of the provider's claims and the supporting documentation for the service under scrutiny. The number of claims in a round is a figure CMS sets; the point is that it is a sample, not the whole book of business.One-on-one education
After the round, the MAC provides individualized education on the specific errors it found — the step that gives the program its name and its purpose. The provider is given time to correct the problems before anything else happens.Repeat, up to a limited number of rounds
A provider who is still making the same errors moves to another round of review and education. CMS caps the number of rounds. A provider who comes into compliance is removed from the process.Escalation after the final round
A provider who remains non-compliant after the final round is referred to CMS, which decides what happens next. That can include further review, placing the provider on 100 percent prepayment review, extrapolation of an error rate to a larger set of claims, or referral to a Recovery Auditor or a program-integrity contractor.
TPE is meant to be the least adversarial review
The Recovery Audit program (RAC)
The Recovery Audit program uses Recovery Audit Contractors (RACs, or Recovery Auditors) to find and correct improper payments in Medicare fee-for-service after claims have been paid. Its mission runs in both directions: it identifies overpayments Medicare should recover and underpayments a provider is owed. The program's authority is section 1893(h) of the Social Security Act, which directs the Secretary to contract with recovery audit contractors to identify underpayments and overpayments and to recoup overpayments.
Two features distinguish a RAC from the MAC's own review. First, Recovery Auditors work purely post-payment, and some of their work is automated — applying rules to claims data without asking for records — while complex review requires a human to read the medical record. Second, and unusually, a Recovery Auditor is paid on a contingency basis: a share of what it recovers, rather than a flat fee, with that fee returned if its finding is later overturned on appeal. Recovery Auditors operate by geographic region.
The RAC finds it; the MAC collects it
Comprehensive Error Rate Testing (CERT)
Comprehensive Error Rate Testing (CERT) is the program CMS uses to measure the Medicare fee-for-service improper payment rate — how much of what the program pays does not meet Medicare's requirements. This is the type most often misunderstood, because a practice caught in a CERT sample experiences it as an audit, but the program's purpose is measurement of the program as a whole, not scrutiny of that provider.
CERT works by drawing a statistically valid random sample of claims from across the program each reporting period and requesting the medical records behind them. A random sample is the point: it lets CMS calculate a rate that reflects all claims the program processed, and it produces breakdowns by contractor, service, and provider type. It is not built to spot a particular provider's billing patterns — because the sample is random, its reviewers generally cannot see the kind of pattern that would signal fraud. The improper payment rate it produces is not a fraud rate; it is a measure of payments that did not meet the rules, for any reason, including missing documentation.
For a CERT request, the records are the whole game
Unified Program Integrity Contractors (UPICs)
A Unified Program Integrity Contractor (UPIC) is the contractor a practice least wants to hear from, because a UPIC's job is not improper payments — it is benefit integrity: detecting, deterring, and investigating potential fraud, waste, and abuse. UPICs work across both Medicare and Medicaid, including the data match between the two programs. They were created by consolidating earlier program-integrity contractors — the Zone Program Integrity Contractors (ZPICs), Program Safeguard Contractors (PSCs), and Medicaid Integrity Contractors (MICs) — into a single integrated function organized by region.
The focus of a UPIC review is different in kind from a MAC's, a CERT sample, or a Recovery Auditor's. Where those ask whether a claim met the rules, a UPIC asks whether the billing reflects what actually happened — whether the service billed was really provided, whether documentation may have been falsified, and whether there are patterns that indicate potential fraud. Because the question is different, so are the tools and the consequences: a UPIC can initiate administrative actions to deny or suspend payments, ensure improper payments are recouped, and refer cases of potential fraud to the HHS Office of Inspector General for consideration of civil or criminal action and administrative sanctions such as exclusion.
A benefit-integrity contact belongs with counsel immediately
The Supplemental Medical Review Contractor (SMRC)
The Supplemental Medical Review Contractor (SMRC) is a single national contractor CMS uses to perform medical review as CMS directs — nationwide reviews of specific topics, services, or vulnerabilities that CMS has identified, often from its own data analysis, the CERT results, professional organizations, or federal oversight agencies. Its purpose is to help lower improper payment rates and protect the Medicare Trust Funds.
What sets the SMRC apart from a MAC's medical review is scope. A MAC reviews within its own jurisdiction; the SMRC is a single contractor conducting one CMS-directed review across the whole country, so a practice anywhere can be included in an SMRC project focused on a particular service. Like the other reviewers, it requests records, denies claims when the documentation does not support them or is not produced, and may use statistical sampling to project a result.
Comparing the audit types
The programs are easiest to keep straight when their purposes are set side by side. The single most useful column is the first data column — what the contractor is actually trying to do — because that is what determines how serious the contact is and who inside the practice should own the response.
| Program | What it is for | Who runs it | Timing | Where it can lead |
|---|---|---|---|---|
| MAC medical review / TPE | Confirm claims meet Medicare's coverage rules; reduce a provider's errors through education (TPE) | The Medicare Administrative Contractor | Prepayment or post-payment | Education and correction; escalation to CMS (prepayment review, extrapolation, or referral) if errors persist |
| Recovery Audit (RAC) | Identify and correct improper payments — overpayments to recover and underpayments to pay | Recovery Auditors, paid on a contingency basis | Post-payment | The MAC adjusts the claim and recoups; the finding is appealable |
| CERT | Measure the program's improper payment rate from a random sample | The CERT contractor, for CMS | Measured after payment | A sampled claim in error is corrected; no records means an automatic error |
| UPIC | Investigate potential fraud, waste, and abuse across Medicare and Medicaid | Unified Program Integrity Contractors | Either — including active investigation | Payment suspension, recoupment, and referral to the OIG for civil, criminal, or administrative action |
| SMRC | Conduct CMS-directed national medical review on specific topics | A single national contractor, for CMS | Typically post-payment | Denials where documentation does not support the claim; results reported to CMS |
The line that matters most runs between the first four rows and the UPIC row: the others are about whether claims were paid correctly, while a UPIC is about whether conduct was fraudulent. That is the difference between a billing matter and a legal one.
What the programs share: records, extrapolation, and appeals
For all their differences, these programs run on a few common mechanics, and knowing them is most of knowing how to respond to any of them.
- The Additional Documentation Request (ADR)
- When a reviewer cannot decide a claim on the information it already has, it asks the provider to send the medical records that support the claim, through an Additional Documentation Request. The ADR is the pivot point of most reviews: MACs, Recovery Auditors, the SMRC, and UPICs all use it, and if no response arrives within the timeframe the contractor sets, they deny the claim — in whole or in part — as not reasonable and necessary. The timeframe is CMS-controlled, so the operative deadline is the one on the request; missing it converts a reviewable claim into a denied one for a reason that had nothing to do with the care.
- Extrapolation
- Rather than review every claim, a contractor may review a statistical sample and project the error rate it finds onto the larger universe of similar claims to calculate a total overpayment. That projection is extrapolation, and it is why a sample of a few claims can produce a demand far larger than the dollars in the sample itself. The sampling and projection methodology is governed by CMS rules; a practice facing an extrapolated overpayment often has grounds to challenge the methodology, not only the individual claims.
- The right to appeal
- A contractor's determination is not the last word. A denial or overpayment finding from these programs is appealable through Medicare's standard five-level fee-for-service appeals process, and filing a timely appeal generally pauses recoupment while the appeal is pending. The deadlines and any dollar thresholds for each level are set by CMS and stated in the determination notice, so the notice itself is where a practice reads the clock it is working against.
What a billing operation should actually do
A practice cannot choose whether to be reviewed, but it can control how ready it is and how it responds. The work is mostly ordinary — the discipline of a practice that documents its care and answers its mail.
- Identify the contractor and the type before reacting. Read the letterhead and the stated reason: a TPE round from the MAC, a Recovery Audit demand, a CERT sample, and a UPIC contact are different situations with different owners inside the practice.
- Treat every Additional Documentation Request as a deadline. The fastest way to lose a claim that was fine is to not send the records on time. Track the request date, the response deadline on the notice, and what was sent.
- Answer a TPE the way it is meant. Send complete documentation, then act on the education. TPE is built to end in correction, not recovery, for a provider who engages with it.
- Escalate a benefit-integrity contact immediately. A UPIC contact, a payment suspension, or anything that reads as a fraud investigation goes to the compliance program and counsel at once — not through the normal appeal-and-refund routine.
- Preserve the record and mind the downstream duty. An audit that confirms an overpayment does not end at the demand: a practice also has its own obligation under the 60-day overpayment rule for overpayments it has identified, and a documented, timely response is what shows good faith across all of it.
Educational, not legal advice
Common questions
What is the difference between a RAC audit and a CERT review?
Purpose. A Recovery Auditor (RAC) reviews already-paid claims to find and recover improper payments, and it is paid a share of what it recovers. CERT (Comprehensive Error Rate Testing) draws a random sample of claims to measure the program's overall improper payment rate — it is measurement, not targeted recovery. A practice experiences both as a records request, but the RAC is looking for money to recover from that practice, while CERT is using the sampled claims to estimate a rate for the whole program. In either case, a sampled or reviewed claim found in error is corrected.
How is a UPIC different from the other Medicare audits?
A UPIC (Unified Program Integrity Contractor) investigates potential fraud, waste, and abuse across Medicare and Medicaid — its question is whether conduct was fraudulent, not just whether a claim met the coverage rules. That makes it the most serious of the reviews: a UPIC can suspend payments, pursue recoupment, and refer a matter to the HHS Office of Inspector General for civil, criminal, or administrative action. A contact from a UPIC should go to the practice's compliance program and counsel immediately, rather than being handled as a routine audit.
What happens if we don't respond to an Additional Documentation Request?
The claim is generally denied. When a reviewer — a MAC, Recovery Auditor, the SMRC, or a UPIC — sends an Additional Documentation Request and no response arrives within the timeframe on the notice, the contractor denies the claim, in whole or in part, as not reasonable and necessary. A claim that would have been payable is lost for a reason unrelated to the care simply because the records were not produced on time. The response deadline is set by CMS and stated on the request, so the notice is what a practice should work from.
Is Targeted Probe and Educate (TPE) something to worry about?
TPE is the least adversarial of the reviews. It is run by the MAC, it targets providers whose billing data stands out, and it pairs a review of a sample of claims with one-on-one education across a limited number of rounds, giving the provider time to correct between them. A provider who sends complete documentation and acts on the education usually comes into compliance and is removed from the process. Escalation to CMS — which can include prepayment review or referral to another contractor — happens only for a provider who remains non-compliant after the final round.
Can we appeal a Medicare audit finding?
Yes. A denial or overpayment determination from these programs is appealable through Medicare's standard five-level fee-for-service appeals process, and filing a timely appeal generally pauses recoupment while the appeal is pending. Where a contractor extrapolated an overpayment from a statistical sample, a practice can often challenge the sampling methodology as well as the individual claims. The filing deadline and any dollar threshold for each appeal level are set by CMS and stated in the determination notice.
Key terms in this article
Defined once, on their own pages.
Continue learning
The duty an audit finding can trigger, the route a fraud finding may take, and the program that keeps a practice audit-ready.
The 60-Day Overpayment Rule
An audit that confirms an overpayment meets the practice's own duty to report and return it — a compliance obligation with its own deadline, separate from the contractor's recovery.
The OIG Self-Disclosure Protocol
When a review — or the practice's own investigation — turns up potential fraud, the voluntary channel to disclose it to the OIG on more favorable terms than being caught.
The Seven Elements of an Effective Compliance Program
Auditing and monitoring is one of the seven elements — the program is what keeps a practice ready for an outside review and decides how to respond to what one finds.
Medicare Overpayments and Recoupment
The recovery mechanics a Recovery Audit finding leads to: how a Medicare contractor demands and recoups an overpayment, usually by withholding from future payments.
Authoritative sources
- 42 U.S.C. § 1395ddd(h) — Use of recovery audit contractors (section 1893(h) of the Social Security Act) (opens in a new tab)
The statutory basis for the Recovery Audit program: the Secretary contracts with recovery audit contractors for the purpose of identifying underpayments and overpayments and recouping overpayments for services paid under Medicare, with contractors paid on a contingent basis only from amounts recovered.
- CMS — Medicare Fee-for-Service Recovery Audit Program (opens in a new tab)
Centers for Medicare & Medicaid Services. The Recovery Audit program's mission to identify and correct improper payments (both overpayments and underpayments), its automated and complex post-payment reviews, the transition of demand-letter issuance to the Medicare Administrative Contractors, contingency-fee payment, and appeals following the standard Medicare claim-determination process.
- CMS — Comprehensive Error Rate Testing (CERT) (opens in a new tab)
Centers for Medicare & Medicaid Services. The program CMS uses to measure the Medicare fee-for-service improper payment rate from a statistically valid random sample of claims; the improper payment rate is a measure of payments that did not meet Medicare requirements, not a fraud rate, and a sampled claim for which records are not submitted is counted as a no-documentation error.
- CMS Medicare Program Integrity Manual (Pub. 100-08), Chapters 3 and 4 (opens in a new tab)
Centers for Medicare & Medicaid Services. The prepayment and post-payment review definitions, the Additional Documentation Request and the rule that MACs, RACs, the SMRC, and UPICs deny a claim when records are not received in the expected timeframe, extrapolation of statistical-sample results to the universe of similar claims, and the benefit-integrity function of program-integrity contractors — including payment suspension and denial, recoupment, and referral of potential fraud to the Office of Inspector General.
- CMS — Unified Program Integrity Contractors (UPICs) (opens in a new tab)
Centers for Medicare & Medicaid Services. The contractors that perform fraud, waste, and abuse detection and investigation across Medicare and Medicaid, consolidating the functions of the former Zone Program Integrity Contractor, Program Safeguard Contractor, and Medicaid Integrity Contractor contracts.
